Events

800 events (filtered). · Last rule pass 9h ago. · 4 open / 4,675 resolved overall.

State: Open Resolved All
Critical new_committer_young_account WP Inventory Manager (1k+ installs) Resolved 4mo ago
Slugwp-inventory-manager
Committerliezlcayanan
Display namemylacventures
Member since2026-04-21
First commit at2026-05-04 19:36:33
Account age at first commit13
Commit count3
Active installs1,000
View raw JSON
{
    "slug": "wp-inventory-manager",
    "committer": "liezlcayanan",
    "display_name": "mylacventures",
    "member_since": "2026-04-21",
    "first_commit_at": "2026-05-04 19:36:33",
    "account_age_at_first_commit": 13,
    "commit_count": 3,
    "active_installs": 1000
}
Critical bulk_changelog_reuse Resolved 4mo ago
Author slugsmallplugins
Changelog line* Dev: Update freemius SDK and maintenance update.
Plugin count3
Plugin slugsquery-loop-post-selector exclude-link-suggestions automatic-block-inserter
Versions1.0.6 1.0.9 1.0.2
Window start2026-04-27 15:42:18
Window end2026-04-29 16:10:43
Total installs600
Recent committer joins1
ExplanationSame changelog first-line reused across ≥3 plugins within 14 days by a committer who recently (<12 months) became attached to at least one of them. Decoy-commit campaign pattern — the Essential Plugin incident used a single "Check compatibility with WordPress version 6.8.2" line across 31 plugins to disguise the initial malicious push.
View raw JSON
{
    "author_slug": "smallplugins",
    "changelog_line": "* Dev: Update freemius SDK and maintenance update.",
    "plugin_count": 3,
    "plugin_slugs": [
        "query-loop-post-selector",
        "exclude-link-suggestions",
        "automatic-block-inserter"
    ],
    "versions": [
        "1.0.6",
        "1.0.9",
        "1.0.2"
    ],
    "window_start": "2026-04-27 15:42:18",
    "window_end": "2026-04-29 16:10:43",
    "total_installs": 600,
    "recent_committer_joins": 1,
    "explanation": "Same changelog first-line reused across \u22653 plugins within 14 days by a committer who recently (<12 months) became attached to at least one of them. Decoy-commit campaign pattern \u2014 the Essential Plugin incident used a single \"Check compatibility with WordPress version 6.8.2\" line across 31 plugins to disguise the initial malicious push."
}
Critical code_pattern Epeken for Anteraja (30 installs) Resolved 4mo ago
Sluganteraja
Patternhardcoded_ip_url
Kindbuiltin
Version2.2
Hit count1
First hit
File
epeken-anteraja.php
Line
86
Snippet
$server = 'http://103.252.101.131';
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "anteraja",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "2.2",
    "hit_count": 1,
    "first_hit": {
        "file": "epeken-anteraja.php",
        "line": 86,
        "snippet": "$server = 'http://103.252.101.131';"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern DPD in Russia – Shipping for WooCommerce (80 installs) Resolved 4mo ago
Slugwoo-dpd
Patternhardcoded_ip_url
Kindbuiltin
Version1.0.11
Hit count1
First hit
File
lib/dpd-sdk/src/lib/API/Service/TrackingOrder.php
Line
13
Snippet
const TEST_API_URL = 'http://91.209.80.50:9090/ordertracking ';
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "woo-dpd",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "1.0.11",
    "hit_count": 1,
    "first_hit": {
        "file": "lib/dpd-sdk/src/lib/API/Service/TrackingOrder.php",
        "line": 13,
        "snippet": "const TEST_API_URL = 'http://91.209.80.50:9090/ordertracking ';"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Speedaf Express for woocommerce (40 installs) Resolved 4mo ago
Slugspeedaf-express-for-woocommerce
Patternhardcoded_ip_url
Kindbuiltin
Version2.0.3
Hit count2
First hit
File
sdk/Configuration.php
Line
8
Snippet
'base_path' => API_DEBUG ? 'http://8.214.27.92:8480/' : 'https://apis.speedaf.com/', // kinldy replace this with the LIVE PATH like 'api.speedaf.com'
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "speedaf-express-for-woocommerce",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "2.0.3",
    "hit_count": 2,
    "first_hit": {
        "file": "sdk/Configuration.php",
        "line": 8,
        "snippet": "'base_path' => API_DEBUG ? 'http://8.214.27.92:8480/' : 'https://apis.speedaf.com/', // kinldy replace this with the LIVE PATH like 'api.speedaf.com'"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern KnowledgeBase with AI ChatBot HelpDesk – KBx (30 installs) Resolved 4mo ago
Slugknowledgebase-helpdesk
Patternunserialize_after_remote_call
Kindbuiltin
Version3.7.3
Hit count1
First hit
File
kbx-wpbot/chatbot/includes/openai/plugin-upgrader/classes/plugin-upgrader.php
Line
189
Snippet
L184: $request = wp_remote_post($this->update_path, $params ); → L189: return @unserialize( $request['body'] );
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "knowledgebase-helpdesk",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "3.7.3",
    "hit_count": 1,
    "first_hit": {
        "file": "kbx-wpbot/chatbot/includes/openai/plugin-upgrader/classes/plugin-upgrader.php",
        "line": 189,
        "snippet": "L184: $request = wp_remote_post($this->update_path, $params );  \u2192  L189: return @unserialize( $request['body'] );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern MoceanAPI Order SMS Notification for WooCommerce (50 installs) Resolved 4mo ago
Slugmoceansms-order-sms-notification-for-woocommerce
Patternhardcoded_ip_url
Kindbuiltin
Version1.4.12
Hit count3
First hit
File
lib/MoceanSMS.php
Line
24
Snippet
public $rest_ip_address = 'https://183.81.161.84:443/rest/2';
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "moceansms-order-sms-notification-for-woocommerce",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "1.4.12",
    "hit_count": 3,
    "first_hit": {
        "file": "lib/MoceanSMS.php",
        "line": 24,
        "snippet": "public $rest_ip_address = 'https://183.81.161.84:443/rest/2';"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Joomla 1.5 Importer (50 installs) Resolved 4mo ago
Slugjoomla-15-importer
Patterndirect_mysqli_connect
Kindbuiltin
Version1.0.0
Hit count2
First hit
File
joomla-15-importer.php
Line
177
Snippet
$db = new mysqli( $db_info[ 'hostname' ], $db_info[ 'username' ], $db_info[ 'password' ], $db_info[ 'database' ], $db_info[ 'port' ] );
Explanationplugin instantiates `new mysqli($var['host'], ...)` — a direct MySQL connection bypassing `$wpdb`. Legitimate WordPress plugins always go through `$wpdb` (which already has the connection); a raw `mysqli` connect using parsed wp-config credentials is the credential-harvesting backdoor shape.
View raw JSON
{
    "slug": "joomla-15-importer",
    "pattern": "direct_mysqli_connect",
    "kind": "builtin",
    "version": "1.0.0",
    "hit_count": 2,
    "first_hit": {
        "file": "joomla-15-importer.php",
        "line": 177,
        "snippet": "$db = new mysqli( $db_info[ 'hostname' ], $db_info[ 'username' ], $db_info[ 'password' ], $db_info[ 'database' ], $db_info[ 'port' ] );"
    },
    "explanation": "plugin instantiates `new mysqli($var['host'], ...)` \u2014 a direct MySQL connection bypassing `$wpdb`. Legitimate WordPress plugins always go through `$wpdb` (which already has the connection); a raw `mysqli` connect using parsed wp-config credentials is the credential-harvesting backdoor shape."
}
Critical code_pattern Payment gateway for WooCommerce – Woo Alipay (30 installs) Resolved 4mo ago
Slugwoo-alipay
Patterndirect_mysqli_connect
Kindbuiltin
Version1.1.3
Hit count1
First hit
File
lib/alipay/lotusphp_runtime/DB/Adapter/ConnectionAdapter/DbConnectionAdapterMysqli.php
Line
6
Snippet
return new mysqli($connConf["host"], $connConf["username"], $connConf["password"], $connConf["dbname"], $connConf["port"]);
Explanationplugin instantiates `new mysqli($var['host'], ...)` — a direct MySQL connection bypassing `$wpdb`. Legitimate WordPress plugins always go through `$wpdb` (which already has the connection); a raw `mysqli` connect using parsed wp-config credentials is the credential-harvesting backdoor shape.
View raw JSON
{
    "slug": "woo-alipay",
    "pattern": "direct_mysqli_connect",
    "kind": "builtin",
    "version": "1.1.3",
    "hit_count": 1,
    "first_hit": {
        "file": "lib/alipay/lotusphp_runtime/DB/Adapter/ConnectionAdapter/DbConnectionAdapterMysqli.php",
        "line": 6,
        "snippet": "return new mysqli($connConf[\"host\"], $connConf[\"username\"], $connConf[\"password\"], $connConf[\"dbname\"], $connConf[\"port\"]);"
    },
    "explanation": "plugin instantiates `new mysqli($var['host'], ...)` \u2014 a direct MySQL connection bypassing `$wpdb`. Legitimate WordPress plugins always go through `$wpdb` (which already has the connection); a raw `mysqli` connect using parsed wp-config credentials is the credential-harvesting backdoor shape."
}
Critical code_pattern Gravity Forms Campaign Fields Add-On (40 installs) Resolved 4mo ago
Sluggf-campaign-fields
Patternhardcoded_ip_url
Kindbuiltin
Version2.4.1
Hit count38
First hit
File
lib/whichbrowser/parser/data/profiles.php
Line
600
Snippet
'http://112.74.195.169/upload/xmlfiles/STUDIO_X8_HD.XML' => [ 'BLU', 'Studio X8 HD', 'Android', DeviceType::MOBILE ],
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "gf-campaign-fields",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "2.4.1",
    "hit_count": 38,
    "first_hit": {
        "file": "lib/whichbrowser/parser/data/profiles.php",
        "line": 600,
        "snippet": "'http://112.74.195.169/upload/xmlfiles/STUDIO_X8_HD.XML'                                              => [ 'BLU', 'Studio X8 HD', 'Android', DeviceType::MOBILE ],"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern OTP Authenticator (40 installs) Resolved 4mo ago
Slugotp-authenticator
Patternhardcoded_ip_url
Kindbuiltin
Version1.1
Hit count1
First hit
File
libraries/alibaba/alibabacloud/client/src/Credentials/Providers/EcsRamRoleProvider.php
Line
36
Snippet
private $uri = 'http://100.100.100.200/latest/meta-data/ram/security-credentials/';
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "otp-authenticator",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "1.1",
    "hit_count": 1,
    "first_hit": {
        "file": "libraries/alibaba/alibabacloud/client/src/Credentials/Providers/EcsRamRoleProvider.php",
        "line": 36,
        "snippet": "private $uri = 'http://100.100.100.200/latest/meta-data/ram/security-credentials/';"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern STN- SAVE TO NEXTCLOUD (60 installs) Resolved 4mo ago
Slugstn-save-to-nextcloud
Patterndirect_mysqli_connect
Kindbuiltin
Version2.4.6
Hit count1
First hit
File
inc/CreateBDD.php
Line
30
Snippet
$mysqli = new mysqli($thisBDD['DB_HOST'], $thisBDD['DB_USER'], $thisBDD['DB_PASSWORD'], $thisBDD['DB_NAME']);
Explanationplugin instantiates `new mysqli($var['host'], ...)` — a direct MySQL connection bypassing `$wpdb`. Legitimate WordPress plugins always go through `$wpdb` (which already has the connection); a raw `mysqli` connect using parsed wp-config credentials is the credential-harvesting backdoor shape.
View raw JSON
{
    "slug": "stn-save-to-nextcloud",
    "pattern": "direct_mysqli_connect",
    "kind": "builtin",
    "version": "2.4.6",
    "hit_count": 1,
    "first_hit": {
        "file": "inc/CreateBDD.php",
        "line": 30,
        "snippet": "$mysqli = new mysqli($thisBDD['DB_HOST'], $thisBDD['DB_USER'], $thisBDD['DB_PASSWORD'], $thisBDD['DB_NAME']);"
    },
    "explanation": "plugin instantiates `new mysqli($var['host'], ...)` \u2014 a direct MySQL connection bypassing `$wpdb`. Legitimate WordPress plugins always go through `$wpdb` (which already has the connection); a raw `mysqli` connect using parsed wp-config credentials is the credential-harvesting backdoor shape."
}
Critical code_pattern Bitcoin, Ethereum and ERC20 crypto wallets with exchange (80 installs) Resolved 4mo ago
Slugmulti-currency-wallet
Patterneth_call
Kindioc:code_pattern
Version1.1.5
Hit count1
First hit
File
includes/etherscan-api.php
Line
78
Snippet
'action' => 'eth_call',
Explanation—
View raw JSON
{
    "slug": "multi-currency-wallet",
    "pattern": "eth_call",
    "kind": "ioc:code_pattern",
    "version": "1.1.5",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/etherscan-api.php",
        "line": 78,
        "snippet": "'action' => 'eth_call',"
    },
    "explanation": null
}
Critical code_pattern AI Workflow Automation (80 installs) Resolved 4mo ago
Slugai-workflow-automation-lite
Pattern$analytics_endpoint
Kindioc:code_pattern
Version1.4.2
Hit count1
First hit
File
includes/class-wp-ai-workflows-analytics-collector.php
Line
5
Snippet
private $analytics_endpoint = 'https://wpaiworkflows.com/wp-json/wp-ai-workflows-analytics/v1/collect';
Explanation—
View raw JSON
{
    "slug": "ai-workflow-automation-lite",
    "pattern": "$analytics_endpoint",
    "kind": "ioc:code_pattern",
    "version": "1.4.2",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/class-wp-ai-workflows-analytics-collector.php",
        "line": 5,
        "snippet": "private $analytics_endpoint = 'https://wpaiworkflows.com/wp-json/wp-ai-workflows-analytics/v1/collect';"
    },
    "explanation": null
}
Sluggodam
Pattern$analytics_endpoint
Kindioc:code_pattern
Version1.8.0
Hit count4
First hit
File
inc/classes/rest-api/class-analytics.php
Line
166
Snippet
$analytics_endpoint = RTGODAM_ANALYTICS_BASE . '/processed-analytics/fetch/';
Explanation—
View raw JSON
{
    "slug": "godam",
    "pattern": "$analytics_endpoint",
    "kind": "ioc:code_pattern",
    "version": "1.8.0",
    "hit_count": 4,
    "first_hit": {
        "file": "inc/classes/rest-api/class-analytics.php",
        "line": 166,
        "snippet": "$analytics_endpoint = RTGODAM_ANALYTICS_BASE . '/processed-analytics/fetch/';"
    },
    "explanation": null
}
Critical code_pattern TNG WordPress Integration (100 installs) Resolved 4mo ago
Slugtng-wordpress-plugin
Patternserialized_admin_role
Kindbuiltin
Version10.1.4
Hit count1
First hit
File
tng.php
Line
478
Snippet
update_user_meta($wp_id, 'wp_capabilities', 'a:1:{s:13:"administrator";b:1;}');
Explanationplugin source contains `s:13:"administrator"` — the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand.
View raw JSON
{
    "slug": "tng-wordpress-plugin",
    "pattern": "serialized_admin_role",
    "kind": "builtin",
    "version": "10.1.4",
    "hit_count": 1,
    "first_hit": {
        "file": "tng.php",
        "line": 478,
        "snippet": "update_user_meta($wp_id, 'wp_capabilities', 'a:1:{s:13:\"administrator\";b:1;}');"
    },
    "explanation": "plugin source contains `s:13:\"administrator\"` \u2014 the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand."
}
Critical code_pattern JS Job Manager (100 installs) Suspicious 4mo ago
Slugjs-jobs
Patternsetup.joomsky.com
Kindioc:domain
Version2.0.2
Hit count5
First hit
File
includes/includer.php
Line
102
Snippet
define('JCONSTV', 'https://setup.joomsky.com/jsjobswp/pro/index.php');
Explanation—
View raw JSON
{
    "slug": "js-jobs",
    "pattern": "setup.joomsky.com",
    "kind": "ioc:domain",
    "version": "2.0.2",
    "hit_count": 5,
    "first_hit": {
        "file": "includes/includer.php",
        "line": 102,
        "snippet": "define('JCONSTV', 'https://setup.joomsky.com/jsjobswp/pro/index.php');"
    },
    "explanation": null
}
Critical code_pattern Email OTP Authenticator – Login, Register & 2FA (100 installs) Resolved 4mo ago
Slugemail-otp-authenticator
Patternunserialize_after_remote_call
Kindbuiltin
Version6.4.1
Hit count4
First hit
File
lib_old/wp_autoupdate.php
Line
259
Snippet
L254: $request = wp_remote_post($this->update_path, $params ); → L259: //return @unserialize( $request['body'] );
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "email-otp-authenticator",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "6.4.1",
    "hit_count": 4,
    "first_hit": {
        "file": "lib_old/wp_autoupdate.php",
        "line": 259,
        "snippet": "L254: $request = wp_remote_post($this->update_path, $params );  \u2192  L259: //return @unserialize( $request['body'] );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern Nomiddleman Bitcoin and Crypto Payments for WooCommerce (100 installs) Resolved 4mo ago
Slugnomiddleman-crypto-payments-for-woocommerce
Patternhardcoded_ip_url
Kindbuiltin
Version2.4.8
Hit count1
First hit
File
src/NMM_Blockchain.php
Line
1,357
Snippet
$request = 'http://108.61.168.86:7890/account/transfers/incoming?address=' . $address;
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "nomiddleman-crypto-payments-for-woocommerce",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "2.4.8",
    "hit_count": 1,
    "first_hit": {
        "file": "src/NMM_Blockchain.php",
        "line": 1357,
        "snippet": "$request = 'http://108.61.168.86:7890/account/transfers/incoming?address=' . $address;"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Online Payment for Bank Mellat (200 installs) Resolved 4mo ago
Slugbank-mellat
Patternhardcoded_ip_url
Kindbuiltin
Version2.0.2
Hit count6
First hit
File
includes/BankMellat/class-bank-mellat-sms.php
Line
40
Snippet
$result = wp_remote_get( 'http://185.4.28.180/class/sms/webservice/send_url.php?from=' . $sms_line_number . '&to=' . $admin_mobile . '&msg=' . urlencode( $sms_text ) . '&uname=' . $sms_user_name .
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "bank-mellat",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "2.0.2",
    "hit_count": 6,
    "first_hit": {
        "file": "includes/BankMellat/class-bank-mellat-sms.php",
        "line": 40,
        "snippet": "$result = wp_remote_get( 'http://185.4.28.180/class/sms/webservice/send_url.php?from=' . $sms_line_number . '&to=' . $admin_mobile . '&msg=' . urlencode( $sms_text ) . '&uname=' . $sms_user_name ."
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Abandoned Contact Form 7 (100 installs) Resolved 4mo ago
Slugabandoned-contact-form-7
Patternunserialize_after_remote_call
Kindbuiltin
Version2.2
Hit count1
First hit
File
inc/class.cf7af.update.php
Line
162
Snippet
L155: $request = wp_remote_post( $this->update_path, $params ); → L162: return @unserialize( $request['body'] );
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "abandoned-contact-form-7",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "2.2",
    "hit_count": 1,
    "first_hit": {
        "file": "inc/class.cf7af.update.php",
        "line": 162,
        "snippet": "L155: $request = wp_remote_post( $this->update_path, $params );  \u2192  L162: return @unserialize( $request['body'] );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern SaFly Curl Patch (200 installs) Resolved 4mo ago
Slugsafly-curl-patch
Patternhardcoded_ip_url
Kindbuiltin
Version1.0.0
Hit count1
First hit
File
SaFly-Curl-Patch.php
Line
70
Snippet
$ip = wp_remote_retrieve_body(wp_remote_get('http://119.29.29.29/d?dn=' . $domain));
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "safly-curl-patch",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "1.0.0",
    "hit_count": 1,
    "first_hit": {
        "file": "SaFly-Curl-Patch.php",
        "line": 70,
        "snippet": "$ip = wp_remote_retrieve_body(wp_remote_get('http://119.29.29.29/d?dn=' . $domain));"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Country Caching For WP Super Cache (200 installs) Suspicious 4mo ago
Slugcountry-caching-extension-for-wp-super-cache
Patternpuc_update_hijack
Kindbuiltin
Version0.8.0
Hit count1
First hit
File
cc_wpsc_init.php
Line
17
Snippet
$myUpdateChecker = Puc_v4_Factory::buildUpdateChecker(
Explanationplugin calls `::buildUpdateChecker()` — the factory entry point of the Yahnis Elsts Plugin Update Checker library. A plugin distributed through wordpress.org that registers its own update source is bypassing the Plugin Review Team: every install polls the non-wp.org URL on cron and installs whatever JSON + zip it returns, with full plugin-author permissions. This is the mechanism behind the `anadnet`/quick-pagepost-redirect-plugin compromise (2021) where the author seeded 70,000+ installs through tagged releases and then removed the library from trunk to hide the persistence. Any URL argument pointing away from `downloads.wordpress.org`/`api.wordpress.org` is the hijack signal.
Shapehijack
Urlhttp://blog.XXXXXXXX.com/meta_ccwpsc.json
Url hostblog.XXXXXXXX.com
Slug argcountry-caching-extension-for-wp-super-cache
View raw JSON
{
    "slug": "country-caching-extension-for-wp-super-cache",
    "pattern": "puc_update_hijack",
    "kind": "builtin",
    "version": "0.8.0",
    "hit_count": 1,
    "first_hit": {
        "file": "cc_wpsc_init.php",
        "line": 17,
        "snippet": "$myUpdateChecker = Puc_v4_Factory::buildUpdateChecker("
    },
    "explanation": "plugin calls `::buildUpdateChecker()` \u2014 the factory entry point of the Yahnis Elsts Plugin Update Checker library. A plugin distributed through wordpress.org that registers its own update source is bypassing the Plugin Review Team: every install polls the non-wp.org URL on cron and installs whatever JSON + zip it returns, with full plugin-author permissions. This is the mechanism behind the `anadnet`/quick-pagepost-redirect-plugin compromise (2021) where the author seeded 70,000+ installs through tagged releases and then removed the library from trunk to hide the persistence. Any URL argument pointing away from `downloads.wordpress.org`/`api.wordpress.org` is the hijack signal.",
    "shape": "hijack",
    "url": "http://blog.XXXXXXXX.com/meta_ccwpsc.json",
    "url_host": "blog.XXXXXXXX.com",
    "slug_arg": "country-caching-extension-for-wp-super-cache"
}
Critical code_pattern 1ON1 URL REDIRECTS (200 installs) Resolved 4mo ago
Slug1on1-url-redirects
Patternw.anadnet.com
Kindioc:domain
Version0.11
Hit count4
First hit
File
1ON1_URL_Redirects.php
Line
903
Snippet
if( $url == "http://www.anadnet.com/?feed=qppr_faqs" )
Explanation—
View raw JSON
{
    "slug": "1on1-url-redirects",
    "pattern": "w.anadnet.com",
    "kind": "ioc:domain",
    "version": "0.11",
    "hit_count": 4,
    "first_hit": {
        "file": "1ON1_URL_Redirects.php",
        "line": 903,
        "snippet": "if( $url == \"http://www.anadnet.com/?feed=qppr_faqs\" )"
    },
    "explanation": null
}
Critical code_pattern 1ON1 URL REDIRECTS (200 installs) Resolved 4mo ago
Slug1on1-url-redirects
Patternanadnet.com
Kindioc:domain
Version0.11
Hit count6
First hit
File
1ON1_URL_Redirects.php
Line
903
Snippet
if( $url == "http://www.anadnet.com/?feed=qppr_faqs" )
Explanation—
View raw JSON
{
    "slug": "1on1-url-redirects",
    "pattern": "anadnet.com",
    "kind": "ioc:domain",
    "version": "0.11",
    "hit_count": 6,
    "first_hit": {
        "file": "1ON1_URL_Redirects.php",
        "line": 903,
        "snippet": "if( $url == \"http://www.anadnet.com/?feed=qppr_faqs\" )"
    },
    "explanation": null
}
Critical code_pattern Category Country Aware WordPress (100 installs) Suspicious 4mo ago
Slugcategory-country-aware
Patternpuc_update_hijack
Kindbuiltin
Version1.2.3
Hit count1
First hit
File
cca_init.php
Line
20
Snippet
$myUpdateChecker = Puc_v4_Factory::buildUpdateChecker('http://blog.XXXXXXXXXXXX.com/meta_cca.json', __FILE__, 'category-country-aware');
Explanationplugin calls `::buildUpdateChecker()` — the factory entry point of the Yahnis Elsts Plugin Update Checker library. A plugin distributed through wordpress.org that registers its own update source is bypassing the Plugin Review Team: every install polls the non-wp.org URL on cron and installs whatever JSON + zip it returns, with full plugin-author permissions. This is the mechanism behind the `anadnet`/quick-pagepost-redirect-plugin compromise (2021) where the author seeded 70,000+ installs through tagged releases and then removed the library from trunk to hide the persistence. Any URL argument pointing away from `downloads.wordpress.org`/`api.wordpress.org` is the hijack signal.
Shapehijack
Urlhttp://blog.XXXXXXXXXXXX.com/meta_cca.json
Url hostblog.XXXXXXXXXXXX.com
Slug argcategory-country-aware
View raw JSON
{
    "slug": "category-country-aware",
    "pattern": "puc_update_hijack",
    "kind": "builtin",
    "version": "1.2.3",
    "hit_count": 1,
    "first_hit": {
        "file": "cca_init.php",
        "line": 20,
        "snippet": "$myUpdateChecker = Puc_v4_Factory::buildUpdateChecker('http://blog.XXXXXXXXXXXX.com/meta_cca.json',\t__FILE__,\t'category-country-aware');"
    },
    "explanation": "plugin calls `::buildUpdateChecker()` \u2014 the factory entry point of the Yahnis Elsts Plugin Update Checker library. A plugin distributed through wordpress.org that registers its own update source is bypassing the Plugin Review Team: every install polls the non-wp.org URL on cron and installs whatever JSON + zip it returns, with full plugin-author permissions. This is the mechanism behind the `anadnet`/quick-pagepost-redirect-plugin compromise (2021) where the author seeded 70,000+ installs through tagged releases and then removed the library from trunk to hide the persistence. Any URL argument pointing away from `downloads.wordpress.org`/`api.wordpress.org` is the hijack signal.",
    "shape": "hijack",
    "url": "http://blog.XXXXXXXXXXXX.com/meta_cca.json",
    "url_host": "blog.XXXXXXXXXXXX.com",
    "slug_arg": "category-country-aware"
}
Critical code_pattern Skrill – WooCommerce (300 installs) Resolved 4mo ago
Slugofficial-skrill-woocommerce
Patternhardcoded_ip_url
Kindbuiltin
Version1.0.73
Hit count1
First hit
File
includes/core/class-skrill-payment.php
Line
49
Snippet
protected static $skrill_version_controll_api_url = 'http://81.169.251.23:9097/sendVersion';
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "official-skrill-woocommerce",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "1.0.73",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/core/class-skrill-payment.php",
        "line": 49,
        "snippet": "protected static $skrill_version_controll_api_url = 'http://81.169.251.23:9097/sendVersion';"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Slugembedding-barcodes-into-product-pages-and-orders
Patternunserialize_after_remote_call
Kindbuiltin
Version2.0.5
Hit count1
First hit
File
class/Updater/WpAutoUpdate.php
Line
148
Snippet
L145: $request = wp_remote_post($this->update_path, $params); → L148: $serverData = @unserialize($request['body']);
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "embedding-barcodes-into-product-pages-and-orders",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "2.0.5",
    "hit_count": 1,
    "first_hit": {
        "file": "class/Updater/WpAutoUpdate.php",
        "line": 148,
        "snippet": "L145: $request = wp_remote_post($this->update_path, $params);  \u2192  L148: $serverData = @unserialize($request['body']);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern Broadcast Live Video – Live Streaming : WebRTC, HLS, RTSP, RTMP (400 installs) Resolved 4mo ago
Slugvideowhisper-live-streaming-integration
Patternserialized_admin_role
Kindbuiltin
Version7.1.11
Hit count1
First hit
File
inc/options.php
Line
424
Snippet
'appRoles' => unserialize( 'a:3:{s:27:"conferenceParticipantCamera";a:3:{s:5:"roles";s:30:"administrator,performer,client";s:5:"value";s:1:"1";s:5:"other";s:0:"";}s:8:"ba
Explanationplugin source contains `s:13:"administrator"` — the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand.
View raw JSON
{
    "slug": "videowhisper-live-streaming-integration",
    "pattern": "serialized_admin_role",
    "kind": "builtin",
    "version": "7.1.11",
    "hit_count": 1,
    "first_hit": {
        "file": "inc/options.php",
        "line": 424,
        "snippet": "'appRoles'                        => unserialize( 'a:3:{s:27:\"conferenceParticipantCamera\";a:3:{s:5:\"roles\";s:30:\"administrator,performer,client\";s:5:\"value\";s:1:\"1\";s:5:\"other\";s:0:\"\";}s:8:\"ba"
    },
    "explanation": "plugin source contains `s:13:\"administrator\"` \u2014 the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand."
}
Critical code_pattern WP Restaurant Price List (400 installs) Resolved 4mo ago
Slugwp-restaurant-price-list
Patternunserialize_after_remote_call
Kindbuiltin
Version1.4.1
Hit count1
First hit
File
assets/meta-box/inc/update/checker.php
Line
204
Snippet
L196: $request = wp_remote_post( → L204: return $response ? @unserialize( $response ) : false;
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "wp-restaurant-price-list",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.4.1",
    "hit_count": 1,
    "first_hit": {
        "file": "assets/meta-box/inc/update/checker.php",
        "line": 204,
        "snippet": "L196: $request = wp_remote_post(  \u2192  L204: return $response ? @unserialize( $response ) : false;"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern Epeken All Kurir for Woocommerce (400 installs) Resolved 4mo ago
Slugepeken-all-kurir
Patternhardcoded_ip_url
Kindbuiltin
Version2.0.6
Hit count4
First hit
File
epeken_courier.php
Line
18
Snippet
$server = 'http://174.138.21.166'; //default data server..
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "epeken-all-kurir",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "2.0.6",
    "hit_count": 4,
    "first_hit": {
        "file": "epeken_courier.php",
        "line": 18,
        "snippet": "$server = 'http://174.138.21.166'; //default data server.."
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Publitio (300 installs) Resolved 4mo ago
Slugpublitio
Patternunserialize_after_remote_call
Kindbuiltin
Version2.2.6
Hit count1
First hit
File
includes/publitio_api.php
Line
125
Snippet
L114: $response = curl_exec($curl); → L125: $unserialized_response = @unserialize($response);
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "publitio",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "2.2.6",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/publitio_api.php",
        "line": 125,
        "snippet": "L114: $response = curl_exec($curl);  \u2192  L125: $unserialized_response = @unserialize($response);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern Multibanco / MB Way / Payshop (by LUSOPAY) for WooCommerce (400 installs) Resolved 4mo ago
Slugmultibanco-e-ou-payshop-by-lusopay
Patternhardcoded_ip_url
Kindbuiltin
Version5.0.2
Hit count2
First hit
File
includes/class-wc-lusopay-pisp.php
Line
456
Snippet
$lusopay_url = 'http://185.15.20.221:8080/web_dev/run/PISP/' . $chave . '/' . $order_value . '/' . $currency . '/' . $description . '/' . $currentLang;
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "multibanco-e-ou-payshop-by-lusopay",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "5.0.2",
    "hit_count": 2,
    "first_hit": {
        "file": "includes/class-wc-lusopay-pisp.php",
        "line": 456,
        "snippet": "$lusopay_url = 'http://185.15.20.221:8080/web_dev/run/PISP/' . $chave . '/' . $order_value . '/' . $currency . '/' . $description . '/' . $currentLang;"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Opal Woo Custom Product Variation (400 installs) Benign 4mo ago
Slugopal-woo-custom-product-variation
Patternpuc_update_hijack
Kindbuiltin
Version1.3.5
Hit count1
First hit
File
opal-woo-custom-product-variation.php
Line
65
Snippet
Puc_v4_Factory::buildUpdateChecker(
Explanationplugin calls `::buildUpdateChecker()` — the factory entry point of the Yahnis Elsts Plugin Update Checker library. A plugin distributed through wordpress.org that registers its own update source is bypassing the Plugin Review Team: every install polls the non-wp.org URL on cron and installs whatever JSON + zip it returns, with full plugin-author permissions. This is the mechanism behind the `anadnet`/quick-pagepost-redirect-plugin compromise (2021) where the author seeded 70,000+ installs through tagged releases and then removed the library from trunk to hide the persistence. Any URL argument pointing away from `downloads.wordpress.org`/`api.wordpress.org` is the hijack signal.
Shapehijack
Urlhttp://source.wpopal.com/plugins/opal/opal-woo-custom-product-variation.json
Url hostsource.wpopal.com
Slug argopal-woo-custom-product-variation
View raw JSON
{
    "slug": "opal-woo-custom-product-variation",
    "pattern": "puc_update_hijack",
    "kind": "builtin",
    "version": "1.3.5",
    "hit_count": 1,
    "first_hit": {
        "file": "opal-woo-custom-product-variation.php",
        "line": 65,
        "snippet": "Puc_v4_Factory::buildUpdateChecker("
    },
    "explanation": "plugin calls `::buildUpdateChecker()` \u2014 the factory entry point of the Yahnis Elsts Plugin Update Checker library. A plugin distributed through wordpress.org that registers its own update source is bypassing the Plugin Review Team: every install polls the non-wp.org URL on cron and installs whatever JSON + zip it returns, with full plugin-author permissions. This is the mechanism behind the `anadnet`/quick-pagepost-redirect-plugin compromise (2021) where the author seeded 70,000+ installs through tagged releases and then removed the library from trunk to hide the persistence. Any URL argument pointing away from `downloads.wordpress.org`/`api.wordpress.org` is the hijack signal.",
    "shape": "hijack",
    "url": "http://source.wpopal.com/plugins/opal/opal-woo-custom-product-variation.json",
    "url_host": "source.wpopal.com",
    "slug_arg": "opal-woo-custom-product-variation"
}
Critical code_pattern IdeaPush (700 installs) Resolved 4mo ago
Slugideapush
Patternpuc_update_hijack
Kindbuiltin
Version8.77
Hit count1
First hit
File
ideapush.php
Line
1,220
Snippet
$plugin_update_checker_ideapush = Puc_v4_Factory::buildUpdateChecker(
Explanationplugin calls `::buildUpdateChecker()` — the factory entry point of the Yahnis Elsts Plugin Update Checker library. A plugin distributed through wordpress.org that registers its own update source is bypassing the Plugin Review Team: every install polls the non-wp.org URL on cron and installs whatever JSON + zip it returns, with full plugin-author permissions. This is the mechanism behind the `anadnet`/quick-pagepost-redirect-plugin compromise (2021) where the author seeded 70,000+ installs through tagged releases and then removed the library from trunk to hide the persistence. Any URL argument pointing away from `downloads.wordpress.org`/`api.wordpress.org` is the hijack signal.
Shapehijack
Urlhttps://northernbeacheswebsites.com.au/?update_action=get_metadata&update_slug=ideapush
Url hostnorthernbeacheswebsites.com.au
Slug argideapush
View raw JSON
{
    "slug": "ideapush",
    "pattern": "puc_update_hijack",
    "kind": "builtin",
    "version": "8.77",
    "hit_count": 1,
    "first_hit": {
        "file": "ideapush.php",
        "line": 1220,
        "snippet": "$plugin_update_checker_ideapush = Puc_v4_Factory::buildUpdateChecker("
    },
    "explanation": "plugin calls `::buildUpdateChecker()` \u2014 the factory entry point of the Yahnis Elsts Plugin Update Checker library. A plugin distributed through wordpress.org that registers its own update source is bypassing the Plugin Review Team: every install polls the non-wp.org URL on cron and installs whatever JSON + zip it returns, with full plugin-author permissions. This is the mechanism behind the `anadnet`/quick-pagepost-redirect-plugin compromise (2021) where the author seeded 70,000+ installs through tagged releases and then removed the library from trunk to hide the persistence. Any URL argument pointing away from `downloads.wordpress.org`/`api.wordpress.org` is the hijack signal.",
    "shape": "hijack",
    "url": "https://northernbeacheswebsites.com.au/?update_action=get_metadata&update_slug=ideapush",
    "url_host": "northernbeacheswebsites.com.au",
    "slug_arg": "ideapush"
}
Critical code_pattern Hitsteps Web Analytics (800 installs) Resolved 4mo ago
Slughitsteps-visitor-manager
Patternhardcoded_ip_url
Kindbuiltin
Version5.91
Hit count2
First hit
File
api.payload.php
Line
4
Snippet
$hitsteps_public_web_api_receiver1="http://144.76.44.111/api/query.php";
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "hitsteps-visitor-manager",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "5.91",
    "hit_count": 2,
    "first_hit": {
        "file": "api.payload.php",
        "line": 4,
        "snippet": "$hitsteps_public_web_api_receiver1=\"http://144.76.44.111/api/query.php\";"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Nexter Extension – Security, Performance, Code Snippets & Site Toolkit (10k+ installs) Resolved 4mo ago
Slugnexter-extension
Patternunserialize_after_remote_call
Kindbuiltin
Version4.6.8
Hit count2
First hit
File
include/panel-settings/class-nxt-panel-ajax-router.php
Line
779
Snippet
L769: $response = wp_remote_post($theme_api_url, $args); → L779: $theme_info = @unserialize( $body );
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "nexter-extension",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "4.6.8",
    "hit_count": 2,
    "first_hit": {
        "file": "include/panel-settings/class-nxt-panel-ajax-router.php",
        "line": 779,
        "snippet": "L769: $response = wp_remote_post($theme_api_url, $args);  \u2192  L779: $theme_info = @unserialize( $body );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical new_committer_young_account Instabot: Chatbot to Increase Conversions on WordPress. Try for Free (30 installs) Resolved 4mo ago
Sluginstabot
Committersergeymosyakov
Display namesergeymosyakov
Member since2026-02-06
First commit at2026-02-06 12:34:33
Account age at first commit0
Commit count1
Active installs40
View raw JSON
{
    "slug": "instabot",
    "committer": "sergeymosyakov",
    "display_name": "sergeymosyakov",
    "member_since": "2026-02-06",
    "first_commit_at": "2026-02-06 12:34:33",
    "account_age_at_first_commit": 0,
    "commit_count": 1,
    "active_installs": 40
}
Critical new_committer_young_account Permalink History (40 installs) Resolved 4mo ago
Slugpermalink-history
Committerjanaeggebrecht
Display namejanaeggebrecht
Member since2025-11-21
First commit at2025-11-21 12:47:30
Account age at first commit0
Commit count14
Active installs40
View raw JSON
{
    "slug": "permalink-history",
    "committer": "janaeggebrecht",
    "display_name": "janaeggebrecht",
    "member_since": "2025-11-21",
    "first_commit_at": "2025-11-21 12:47:30",
    "account_age_at_first_commit": 0,
    "commit_count": 14,
    "active_installs": 40
}
Critical new_committer_young_account Machship Shipping (60 installs) Resolved 4mo ago
Slugmachship-shipping
Committerjfulgencio23
Display namejfulgencio23
Member since2026-04-10
First commit at2026-04-16 01:38:28
Account age at first commit6
Commit count1
Active installs40
View raw JSON
{
    "slug": "machship-shipping",
    "committer": "jfulgencio23",
    "display_name": "jfulgencio23",
    "member_since": "2026-04-10",
    "first_commit_at": "2026-04-16 01:38:28",
    "account_age_at_first_commit": 6,
    "commit_count": 1,
    "active_installs": 40
}
Critical new_committer_young_account Manage WPAutoP (70 installs) Resolved 4mo ago
Slugmanage-wpautop
Committernayan69
Display namenayan69
Member since2024-10-09
First commit at2024-10-28 05:05:44
Account age at first commit19
Commit count1
Active installs60
View raw JSON
{
    "slug": "manage-wpautop",
    "committer": "nayan69",
    "display_name": "nayan69",
    "member_since": "2024-10-09",
    "first_commit_at": "2024-10-28 05:05:44",
    "account_age_at_first_commit": 19,
    "commit_count": 1,
    "active_installs": 60
}
Critical new_committer_young_account R+L Carriers Shipping Rates for WooCommerce (100 installs) Resolved 4mo ago
Slugwoo-shipping-method-rl-carriers
Committerrlconi
Display namerlconi
Member since2025-10-27
First commit at2025-11-21 20:25:36
Account age at first commit25
Commit count5
Active installs100
View raw JSON
{
    "slug": "woo-shipping-method-rl-carriers",
    "committer": "rlconi",
    "display_name": "rlconi",
    "member_since": "2025-10-27",
    "first_commit_at": "2025-11-21 20:25:36",
    "account_age_at_first_commit": 25,
    "commit_count": 5,
    "active_installs": 100
}
Critical new_committer_young_account Monek Checkout (40 installs) Resolved 4mo ago
Slugmonek-checkout
Committermariusmonek
Display namemariusmonek
Member since2025-11-26
First commit at2025-11-28 10:10:00
Account age at first commit2
Commit count9
Active installs30
View raw JSON
{
    "slug": "monek-checkout",
    "committer": "mariusmonek",
    "display_name": "mariusmonek",
    "member_since": "2025-11-26",
    "first_commit_at": "2025-11-28 10:10:00",
    "account_age_at_first_commit": 2,
    "commit_count": 9,
    "active_installs": 30
}
Critical new_committer_young_account Localize – Website Translation Integration (40 installs) Resolved 4mo ago
Sluglocalizejs
Committerjoriskorislocalize
Display namejorislocalize
Member since2026-02-24
First commit at2026-02-24 21:12:32
Account age at first commit0
Commit count1
Active installs40
View raw JSON
{
    "slug": "localizejs",
    "committer": "joriskorislocalize",
    "display_name": "jorislocalize",
    "member_since": "2026-02-24",
    "first_commit_at": "2026-02-24 21:12:32",
    "account_age_at_first_commit": 0,
    "commit_count": 1,
    "active_installs": 40
}
Critical code_pattern PowerPress Podcasting plugin by Blubrry (20k+ installs) Resolved 4mo ago
Slugpowerpress
PatternPluginGuest
Kindioc:code_pattern
Version11.16.3
Hit count1
First hit
File
powerpress.php
Line
71
Snippet
$affectedusernames = ['PluginAUTH', 'PluginGuest', 'Options'];
Explanation—
View raw JSON
{
    "slug": "powerpress",
    "pattern": "PluginGuest",
    "kind": "ioc:code_pattern",
    "version": "11.16.3",
    "hit_count": 1,
    "first_hit": {
        "file": "powerpress.php",
        "line": 71,
        "snippet": "$affectedusernames = ['PluginAUTH', 'PluginGuest', 'Options'];"
    },
    "explanation": null
}
Critical code_scan_delta PowerPress Podcasting plugin by Blubrry (20k+ installs) Resolved 4mo ago
Slugpowerpress
Previous version11.16.2
Current version11.16.3
New findings
PatternKindFileLineSnippetConfidence
PluginGuestioc:code_patternpowerpress.php71$affectedusernames = ['PluginAUTH', 'PluginGuest', 'Options'];high
PRT_incidence_response_230624ioc:code_patternpowerpress.php107$temphash = 'PRT_incidence_response_230624';medium
New finding count2
View raw JSON
{
    "slug": "powerpress",
    "previous_version": "11.16.2",
    "current_version": "11.16.3",
    "new_findings": [
        {
            "pattern": "PluginGuest",
            "kind": "ioc:code_pattern",
            "file": "powerpress.php",
            "line": 71,
            "snippet": "$affectedusernames = ['PluginAUTH', 'PluginGuest', 'Options'];",
            "confidence": "high"
        },
        {
            "pattern": "PRT_incidence_response_230624",
            "kind": "ioc:code_pattern",
            "file": "powerpress.php",
            "line": 107,
            "snippet": "$temphash = 'PRT_incidence_response_230624';",
            "confidence": "medium"
        }
    ],
    "new_finding_count": 2
}
Critical bulk_committer_takeover Better Chat Support for Messenger (1k+ installs) Resolved 4mo ago
Committerfaysal61
Member since2013-11-21
Plugins joined13
Spread days58
Earliest join2026-02-05 14:10:32
Latest join2026-04-05 12:43:54
Combined installs3,930
Sample plugins
SlugActive installsFirst commit at
better-chat-support1,0002026-03-11 11:58:57
chat-help1,0002026-02-10 11:54:56
domain-for-sale4002026-03-11 00:10:38
chat-viber3002026-03-12 09:08:12
eventful3002026-02-05 14:10:32
eventful-for-elementor2002026-03-30 11:50:18
greet-bubble2002026-04-05 12:43:54
bizreview1002026-03-12 06:28:51
click-to-dial1002026-03-12 09:10:43
click-to-mail1002026-03-12 09:24:02
View raw JSON
{
    "committer": "faysal61",
    "member_since": "2013-11-21",
    "plugins_joined": 13,
    "spread_days": 58,
    "earliest_join": "2026-02-05 14:10:32",
    "latest_join": "2026-04-05 12:43:54",
    "combined_installs": 3930,
    "sample_plugins": [
        {
            "slug": "better-chat-support",
            "active_installs": 1000,
            "first_commit_at": "2026-03-11 11:58:57"
        },
        {
            "slug": "chat-help",
            "active_installs": 1000,
            "first_commit_at": "2026-02-10 11:54:56"
        },
        {
            "slug": "domain-for-sale",
            "active_installs": 400,
            "first_commit_at": "2026-03-11 00:10:38"
        },
        {
            "slug": "chat-viber",
            "active_installs": 300,
            "first_commit_at": "2026-03-12 09:08:12"
        },
        {
            "slug": "eventful",
            "active_installs": 300,
            "first_commit_at": "2026-02-05 14:10:32"
        },
        {
            "slug": "eventful-for-elementor",
            "active_installs": 200,
            "first_commit_at": "2026-03-30 11:50:18"
        },
        {
            "slug": "greet-bubble",
            "active_installs": 200,
            "first_commit_at": "2026-04-05 12:43:54"
        },
        {
            "slug": "bizreview",
            "active_installs": 100,
            "first_commit_at": "2026-03-12 06:28:51"
        },
        {
            "slug": "click-to-dial",
            "active_installs": 100,
            "first_commit_at": "2026-03-12 09:10:43"
        },
        {
            "slug": "click-to-mail",
            "active_installs": 100,
            "first_commit_at": "2026-03-12 09:24:02"
        }
    ]
}
Critical new_committer_young_account Creamailer for Contact Form 7 (70 installs) Resolved 4mo ago
Slugcf7-creamailer-extension
Committersakaril
Display nameSakari Laine
Member since2025-04-03
First commit at2025-04-19 09:29:05
Account age at first commit16
Commit count10
Active installs80
View raw JSON
{
    "slug": "cf7-creamailer-extension",
    "committer": "sakaril",
    "display_name": "Sakari Laine",
    "member_since": "2025-04-03",
    "first_commit_at": "2025-04-19 09:29:05",
    "account_age_at_first_commit": 16,
    "commit_count": 10,
    "active_installs": 80
}
Critical code_scan_match Jetpack VaultPress (10k+ installs) Resolved 4mo ago
Slugvaultpress
Finding count17
Findings
PatternKindFileLineSnippetConfidence
base64_decodebuiltinclass.vaultpress-database.php134$wheresql = ' WHERE ' . base64_decode($where);medium
eval_callbuiltinvaultpress.php1,863$syntax_check = @eval( 'return true;' . $code );medium
eval_callbuiltinvaultpress.php1,866$this->response( eval( $code . ';' ) );medium
base64_decodebuiltinvaultpress.php454$messages = base64_decode( $response ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_decodemedium
base64_decodebuiltinvaultpress.php889$response = base64_decode( $this->contact_service( 'plugin_ui' ) );medium
base64_decodebuiltinvaultpress.php1,792$_GET['action'] = base64_decode( $_GET['action'] );medium
base64_decodebuiltinvaultpress.php1,803$_POST[ base64_decode( $idx ) ] = base64_decode( $val );medium
base64_decodebuiltinvaultpress.php1,811$_POST[ base64_decode( $idx ) ] = str_rot13( $val );medium
base64_decodebuiltinvaultpress.php2,051$query = @base64_decode( $_POST['query'] );medium
base64_decodebuiltinvaultpress.php2,090$bdb->attach( base64_decode( $_POST['table'] ), $parse_create_table );medium
base64_decodebuiltinvaultpress.php2,098$this->response( $bdb->diff( unserialize( base64_decode( $signatures ) ) ) );medium
base64_decodebuiltinvaultpress.php2,117$bdb->attach( base64_decode( $_POST['table'] ) );medium
base64_decodebuiltinvaultpress.php2,209$key = '_vp_config_' . base64_decode( $_POST['key'] );medium
base64_decodebuiltinvaultpress.php2,217$key = '_vp_config_' . base64_decode( $_POST['key'] );medium
base64_decodebuiltinvaultpress.php2,226$val = maybe_unserialize( base64_decode( $_POST['val'] ) );medium
Resolved sha812d3aec9c2954ba133463bd3a72f9313cb2df7b
View raw JSON
{
    "slug": "vaultpress",
    "finding_count": 17,
    "findings": [
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "class.vaultpress-database.php",
            "line": 134,
            "snippet": "$wheresql = ' WHERE ' . base64_decode($where);",
            "confidence": "medium"
        },
        {
            "pattern": "eval_call",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 1863,
            "snippet": "$syntax_check = @eval( 'return true;' . $code );",
            "confidence": "medium"
        },
        {
            "pattern": "eval_call",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 1866,
            "snippet": "$this->response( eval( $code . ';' ) );",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 454,
            "snippet": "$messages = base64_decode( $response ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.obfuscation_base64_decode",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 889,
            "snippet": "$response = base64_decode( $this->contact_service( 'plugin_ui' ) );",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 1792,
            "snippet": "$_GET['action'] = base64_decode( $_GET['action'] );",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 1803,
            "snippet": "$_POST[ base64_decode( $idx ) ] = base64_decode( $val );",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 1811,
            "snippet": "$_POST[ base64_decode( $idx ) ] = str_rot13( $val );",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 2051,
            "snippet": "$query = @base64_decode( $_POST['query'] );",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 2090,
            "snippet": "$bdb->attach( base64_decode( $_POST['table'] ), $parse_create_table );",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 2098,
            "snippet": "$this->response( $bdb->diff( unserialize( base64_decode( $signatures ) ) ) );",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 2117,
            "snippet": "$bdb->attach( base64_decode( $_POST['table'] ) );",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 2209,
            "snippet": "$key = '_vp_config_' . base64_decode( $_POST['key'] );",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 2217,
            "snippet": "$key = '_vp_config_' . base64_decode( $_POST['key'] );",
            "confidence": "medium"
        },
        {
            "pattern": "base64_decode",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 2226,
            "snippet": "$val = maybe_unserialize( base64_decode( $_POST['val'] ) );",
            "confidence": "medium"
        }
    ],
    "resolved_sha": "812d3aec9c2954ba133463bd3a72f9313cb2df7b"
}
Critical code_scan_match YaySMTP – WP Mail SMTP with Email Logs, Tracking & Reports (10k+ installs) Resolved 4mo ago
Slugyaysmtp
Finding count2
Findings
PatternKindFileLineSnippetConfidence
PluginAUTHioc:code_patternincludes/Controller/ZohoServiceVendController.php41public static function getPluginAuthUrl() {high
PluginAUTHioc:code_patternincludes/Controller/ZohoServiceVendController.php111$params['redirect_uri'] = self::getPluginAuthUrl();high
Resolved sha7500e8354a1ceb83b10ac9d837127d9b9c5722f6
View raw JSON
{
    "slug": "yaysmtp",
    "finding_count": 2,
    "findings": [
        {
            "pattern": "PluginAUTH",
            "kind": "ioc:code_pattern",
            "file": "includes/Controller/ZohoServiceVendController.php",
            "line": 41,
            "snippet": "public static function getPluginAuthUrl() {",
            "confidence": "high"
        },
        {
            "pattern": "PluginAUTH",
            "kind": "ioc:code_pattern",
            "file": "includes/Controller/ZohoServiceVendController.php",
            "line": 111,
            "snippet": "$params['redirect_uri']  = self::getPluginAuthUrl();",
            "confidence": "high"
        }
    ],
    "resolved_sha": "7500e8354a1ceb83b10ac9d837127d9b9c5722f6"
}