Category: Last patch

Patching an Arbitrary Plugin Disablement Bug in the “webmaster-tools-verification” Plugin

Published on November 29, 2022

Welcome to Patchstack’s “Last Patch”. This is a short series of blog posts where we will be discussing and patching unpatched security bugs in open-source projects. With an initial focus on plugins found in the WordPress.org plugin repository This post will review the webmaster-tools-verification plugin. This plugin was first created in 2009 and is extremely simple […]

Read more →

Patching Remote Code Execution in the ‘member-hero’ Plugin

Published on November 15, 2022

Welcome to Patchstack’s “Last Patch”. This is a short series of blog posts where we will be discussing and patching unpatched security bugs in open-source projects. With an initial focus on plugins found in the WordPress.org plugin repository Today I will be discussing how to address an unauthenticated remote code execution vulnerability in the member-hero plugin. […]

Read more →