Proceedings of the Evaluation and Assessment on Software Engineering 2019
DOI: 10.1145/3319008.3319029
|View full text |Cite
|
Sign up to set email alerts
|

A Demand-Side Viewpoint to Software Vulnerabilities in WordPress Plugins

Abstract: WordPress has long been the most popular content management system (CMS). This CMS powers millions and millions of websites. Although WordPress has had a particularly bad track record in terms of security, in recent years many of the well-known security risks have transmuted from the core WordPress to the numerous plugins and themes written for the CMS. Given this background, the paper analyzes known software vulnerabilities discovered from WordPress plugins. A demand-side viewpoint was used to motivate the an… Show more

Help me understand this report
View preprint versions

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
7
0

Year Published

2019
2019
2024
2024

Publication Types

Select...
5
3

Relationship

1
7

Authors

Journals

citations
Cited by 10 publications
(7 citation statements)
references
References 32 publications
0
7
0
Order By: Relevance
“…Bug fixing times are a classical topic in software engineering. Although not all bugs found by fuzzing are security bugs, previous results generally indicate that also security bugs often take a surprisingly long time to fix in many different contexts [15], [16]. Some bugs are never fixed even though these have been recognized as vulnerabilities [17].…”
Section: Research Design a Research Questionsmentioning
confidence: 95%
See 1 more Smart Citation
“…Bug fixing times are a classical topic in software engineering. Although not all bugs found by fuzzing are security bugs, previous results generally indicate that also security bugs often take a surprisingly long time to fix in many different contexts [15], [16]. Some bugs are never fixed even though these have been recognized as vulnerabilities [17].…”
Section: Research Design a Research Questionsmentioning
confidence: 95%
“…No universal explanation is known for these and related results. Numerous different explanations are offered in the literature: some build on bug triaging aspects and different incentives for vendors, bug reporters, and developers [15], [18]; others stem from bug severity, testing, architectural flaws, dependencies, code complexity, and code churn [19], [20]; some are related to problems in vulnerability disclosure and associated coordination, including the allocation of CVEs for the vulnerabilities [16], [21]; and so forth. Whatever the explanations may be, the first research question is worth asking to better understand the time delays associated with continuous fuzzing and automated testing in general.…”
Section: Research Design a Research Questionsmentioning
confidence: 99%
“…Authors [4] review existing CAPTCHA schemes to protect various Web services. Authors explains that textbased CAPTCHAs have become suffi ciently hard for humans to solve and thus their usability has decreased at least for an ordinary user.…”
Section: State Of the Artmentioning
confidence: 99%
“…is may disturb other applications during the upgradation of the PHP version if there is a shared server to save the operational cost of hosting or any old version of PHP framework such as WordPress in use that can be also more dangerous for web application services [3]. With these vulnerable frameworks, the attacker can delete databases or ask for a ransom to restore those databases or encrypted code.…”
Section: Introductionmentioning
confidence: 99%