Hello list! I want to warn you about Cross-Site Scripting and Insufficient Anti-automation vulnerabilities in Wordfence Security for WordPress. Wordfence - it's security plugin for WordPress. ------------------------- Affected products: ------------------------- Vulnerable are Wordfence Security 3.3.5 and previous versions. ---------- Details: ---------- XSS (WASC-08): Wordfence Security XSS.html Wordfence Security XSS exploit (C) 2012 MustLive. http://websecurity.com.ua
Insufficient Anti-automation (WASC-21): Wordfence Security IAA.html Wordfence Security IAA exploit (C) 2012 MustLive. http://websecurity.com.ua
I've informed the plugin developer about vulnerabilities. And mentioned about these vulnerabilities at my site (http://websecurity.com.ua/6106/). Best wishes & regards, MustLive Administrator of Websecurity web site http://websecurity.com.ua