Events

800 events (filtered). · Last rule pass 9h ago. · 4 open / 4,675 resolved overall.

State: Open Resolved All
Critical code_pattern aapanel WP Toolkit (1k+ installs) Resolved 5mo ago
Slugaapanel-wp-toolkit
Patternserialized_admin_role
Kindbuiltin
Version1.2
Hit count1
First hit
File
includes/class-aapanel-wp-toolkit-agent.php
Line
47
Snippet
$user_id = $wpdb->get_var("select `user_id` from " . $wpdb->usermeta . " where `meta_key` = '" . $wpdb->prefix . "capabilities' and `meta_value` like '%s:13:\"administrator\";b:1;%'"); // retrieve s
Explanationplugin source contains `s:13:"administrator"` — the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand.
View raw JSON
{
    "slug": "aapanel-wp-toolkit",
    "pattern": "serialized_admin_role",
    "kind": "builtin",
    "version": "1.2",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/class-aapanel-wp-toolkit-agent.php",
        "line": 47,
        "snippet": "$user_id = $wpdb->get_var(\"select `user_id` from \" . $wpdb->usermeta . \" where `meta_key` = '\" . $wpdb->prefix . \"capabilities' and `meta_value` like '%s:13:\\\"administrator\\\";b:1;%'\"); // retrieve s"
    },
    "explanation": "plugin source contains `s:13:\"administrator\"` \u2014 the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand."
}
Slugbit-pi
PatternPluginAUTH
Kindioc:code_pattern
Version1.19.0
Hit count6
First hit
File
backend/app/src/Authorization/AuthorizationFactory.php
Line
78
Snippet
$freePluginAuthorizationClass = NodeExecutor::BASE_INTEGRATION_NAMESPACE . "{$appSlug}\\{$appSlug}Authorization";
Explanation—
View raw JSON
{
    "slug": "bit-pi",
    "pattern": "PluginAUTH",
    "kind": "ioc:code_pattern",
    "version": "1.19.0",
    "hit_count": 6,
    "first_hit": {
        "file": "backend/app/src/Authorization/AuthorizationFactory.php",
        "line": 78,
        "snippet": "$freePluginAuthorizationClass = NodeExecutor::BASE_INTEGRATION_NAMESPACE . \"{$appSlug}\\\\{$appSlug}Authorization\";"
    },
    "explanation": null
}
Critical code_pattern FV Player 8 (1k+ installs) Resolved 5mo ago
Slugfv-player
Patternunserialize_after_remote_call
Kindbuiltin
Version8.1.4
Hit count1
First hit
File
includes/fp-api-private.php
Line
249
Snippet
L239: $raw_response = wp_remote_post( $this->strPrivateAPI, $request ); → L249: $response = @unserialize( preg_replace( '~^/\*[\s\S]*?\*/\s+~', '', $raw_respons
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "fv-player",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "8.1.4",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/fp-api-private.php",
        "line": 249,
        "snippet": "L239: $raw_response = wp_remote_post( $this->strPrivateAPI, $request );  \u2192  L249: $response = @unserialize( preg_replace( '~^/\\*[\\s\\S]*?\\*/\\s+~', '', $raw_respons"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern Yektanet Ecommerce (900 installs) Resolved 5mo ago
Slugyektanet-ecommerce
Patternhardcoded_ip_url
Kindbuiltin
Version1.1.6
Hit count2
First hit
File
settings/vars.php
Line
8
Snippet
$product_update_api_url = 'http://87.247.185.150/products';
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "yektanet-ecommerce",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "1.1.6",
    "hit_count": 2,
    "first_hit": {
        "file": "settings/vars.php",
        "line": 8,
        "snippet": "$product_update_api_url = 'http://87.247.185.150/products';"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern WappPress – Convert Site to App Fast – WordPress to Mobile App Builder (1k+ installs) Resolved 5mo ago
Slugwapppress-builds-android-app-for-website
Patternhardcoded_ip_url
Kindbuiltin
Version8.0.0
Hit count1
First hit
File
includes/wappPress_admin_setting.php
Line
2,524
Snippet
$ip = 'http://199.38.85.107/aapi';
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "wapppress-builds-android-app-for-website",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "8.0.0",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/wappPress_admin_setting.php",
        "line": 2524,
        "snippet": "$ip = 'http://199.38.85.107/aapi';"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern iControlWP (1k+ installs) Resolved 5mo ago
Slugworpit-admin-dashboard-plugin
PatternPluginAUTH
Kindioc:code_pattern
Version5.5.4
Hit count8
First hit
File
src/features/plugin.php
Line
46
Snippet
'sAuthKey' => $this->getPluginAuthKey(),
Explanation—
View raw JSON
{
    "slug": "worpit-admin-dashboard-plugin",
    "pattern": "PluginAUTH",
    "kind": "ioc:code_pattern",
    "version": "5.5.4",
    "hit_count": 8,
    "first_hit": {
        "file": "src/features/plugin.php",
        "line": 46,
        "snippet": "'sAuthKey'                  => $this->getPluginAuthKey(),"
    },
    "explanation": null
}
Critical code_pattern Operation Demo Importer – Demo Importer For WPoperation Themes (900 installs) Resolved 5mo ago
Slugoperation-demo-importer
Patternunserialize_after_remote_call
Kindbuiltin
Version1.2.0
Hit count1
First hit
File
classes/importers/class-settings-importer.php
Line
44
Snippet
L28: $contents = curl_exec($ch); → L44: $data = @unserialize( $raw );
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "operation-demo-importer",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.2.0",
    "hit_count": 1,
    "first_hit": {
        "file": "classes/importers/class-settings-importer.php",
        "line": 44,
        "snippet": "L28: $contents = curl_exec($ch);  \u2192  L44: $data = @unserialize( $raw );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern Formidable PRO2PDF (1k+ installs) Resolved 5mo ago
Slugformidablepro-2-pdf
Patternunserialize_after_remote_call
Kindbuiltin
Version3.23
Hit count1
First hit
File
fpropdf.php
Line
604
Snippet
L591: $request = wp_remote_get($url); → L604: $files = @unserialize($row['value']);
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "formidablepro-2-pdf",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "3.23",
    "hit_count": 1,
    "first_hit": {
        "file": "fpropdf.php",
        "line": 604,
        "snippet": "L591: $request = wp_remote_get($url);  \u2192  L604: $files = @unserialize($row['value']);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Slugbarcode-scanner-lite-pos-to-manage-products-inventory-and-orders
Patternunserialize_after_remote_call
Kindbuiltin
Version1.12.1
Hit count1
First hit
File
src/features/updater/WpAutoUpdate.php
Line
149
Snippet
L146: $request = wp_remote_post($this->update_path, $params); → L149: $serverData = @unserialize($request['body']);
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "barcode-scanner-lite-pos-to-manage-products-inventory-and-orders",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.12.1",
    "hit_count": 1,
    "first_hit": {
        "file": "src/features/updater/WpAutoUpdate.php",
        "line": 149,
        "snippet": "L146: $request = wp_remote_post($this->update_path, $params);  \u2192  L149: $serverData = @unserialize($request['body']);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Sluga4-barcode-generator
Patternunserialize_after_remote_call
Kindbuiltin
Version3.4.12
Hit count1
First hit
File
class/Updater/WpAutoUpdate.php
Line
148
Snippet
L145: $request = wp_remote_post($this->update_path, $params); → L148: $serverData = @unserialize($request['body']);
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "a4-barcode-generator",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "3.4.12",
    "hit_count": 1,
    "first_hit": {
        "file": "class/Updater/WpAutoUpdate.php",
        "line": 148,
        "snippet": "L145: $request = wp_remote_post($this->update_path, $params);  \u2192  L148: $serverData = @unserialize($request['body']);"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern WPOSS阿里云对象存储 (900 installs) Resolved 5mo ago
Slugwposs
Patternhardcoded_ip_url
Kindbuiltin
Version5.0
Hit count1
First hit
File
sdk/aliyun-oss-php-sdk/src/OSS/OssClient.php
Line
2,705
Snippet
const OSS_HOST_TYPE_IP = "ip"; //http://1.1.1.1/bucket/object
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "wposs",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "5.0",
    "hit_count": 1,
    "first_hit": {
        "file": "sdk/aliyun-oss-php-sdk/src/OSS/OssClient.php",
        "line": 2705,
        "snippet": "const OSS_HOST_TYPE_IP = \"ip\";  //http://1.1.1.1/bucket/object"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Awesome Support – WordPress HelpDesk & Support Plugin (6k+ installs) Resolved 5mo ago
Slugawesome-support
Patternunserialize_after_remote_call
Kindbuiltin
Version6.3.8
Hit count1
First hit
File
includes/gas-framework/inc/scssphp/scss.inc.php
Line
3,675
Snippet
L3670: $response = wp_remote_get($icache); → L3675: $imports = @unserialize( $body, ['allowed_classes' => false] );
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "awesome-support",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "6.3.8",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/gas-framework/inc/scssphp/scss.inc.php",
        "line": 3675,
        "snippet": "L3670: $response = wp_remote_get($icache);  \u2192  L3675: $imports = @unserialize( $body, ['allowed_classes' => false] );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern SoftTech-IT bKash, Rocket, Nagad (6k+ installs) Resolved 5mo ago
Slugbkash
Patternhardcoded_ip_url
Kindbuiltin
Version2.4
Hit count1
First hit
File
index.php
Line
82
Snippet
( http://66.45.237.70/api.php )</p>
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "bkash",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "2.4",
    "hit_count": 1,
    "first_hit": {
        "file": "index.php",
        "line": 82,
        "snippet": "( http://66.45.237.70/api.php )</p>"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Envato Toolkit (5k+ installs) Resolved 5mo ago
Slugtoolkit-for-envato
PatternPluginAUTH
Kindioc:code_pattern
Version1.4
Hit count12
First hit
File
Models/class.EnvatoAPIManager.php
Line
393
Snippet
* @param string $paramPluginAuthor
Explanation—
View raw JSON
{
    "slug": "toolkit-for-envato",
    "pattern": "PluginAUTH",
    "kind": "ioc:code_pattern",
    "version": "1.4",
    "hit_count": 12,
    "first_hit": {
        "file": "Models/class.EnvatoAPIManager.php",
        "line": 393,
        "snippet": "* @param string $paramPluginAuthor"
    },
    "explanation": null
}
Critical code_pattern Wise Chat (5k+ installs) Resolved 5mo ago
Slugwise-chat
Patterndirect_mysqli_connect
Kindbuiltin
Version3.4
Hit count1
First hit
File
src/Endpoints/Ultra/index.php
Line
70
Snippet
$dbWC = new mysqli($constants['DB_HOST'], $constants['DB_USER'], $constants['DB_PASSWORD'], $constants['DB_NAME']);
Explanationplugin instantiates `new mysqli($var['host'], ...)` — a direct MySQL connection bypassing `$wpdb`. Legitimate WordPress plugins always go through `$wpdb` (which already has the connection); a raw `mysqli` connect using parsed wp-config credentials is the credential-harvesting backdoor shape.
View raw JSON
{
    "slug": "wise-chat",
    "pattern": "direct_mysqli_connect",
    "kind": "builtin",
    "version": "3.4",
    "hit_count": 1,
    "first_hit": {
        "file": "src/Endpoints/Ultra/index.php",
        "line": 70,
        "snippet": "$dbWC = new mysqli($constants['DB_HOST'], $constants['DB_USER'], $constants['DB_PASSWORD'], $constants['DB_NAME']);"
    },
    "explanation": "plugin instantiates `new mysqli($var['host'], ...)` \u2014 a direct MySQL connection bypassing `$wpdb`. Legitimate WordPress plugins always go through `$wpdb` (which already has the connection); a raw `mysqli` connect using parsed wp-config credentials is the credential-harvesting backdoor shape."
}
Critical code_pattern RSFirewall! (4k+ installs) Resolved 5mo ago
Slugrsfirewall
Patternunserialize_after_remote_call
Kindbuiltin
Version1.1.46
Hit count1
First hit
File
libraries/autoupdate.php
Line
180
Snippet
L176: $request = wp_remote_post($this->update_path, $params ); → L180: return @unserialize( $request['body'] );
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "rsfirewall",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.1.46",
    "hit_count": 1,
    "first_hit": {
        "file": "libraries/autoupdate.php",
        "line": 180,
        "snippet": "L176: $request = wp_remote_post($this->update_path, $params );  \u2192  L180: return @unserialize( $request['body'] );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern Shopping Cart & eCommerce Store (3k+ installs) Resolved 5mo ago
Slugwp-easycart
Patternhardcoded_ip_url
Kindbuiltin
Version5.8.14
Hit count1
First hit
File
inc/aws/Aws/data/s3/2006-03-01/endpoint-tests-1.json.php
Line
3
Snippet
return [ 'testCases' => [ [ 'documentation' => 'region is not a valid DNS-suffix', 'expect' => [ 'error' => 'Invalid region: region was not a valid DNS name.', ], 'params' => [ 'Region' => 'a b', 'Use
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "wp-easycart",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "5.8.14",
    "hit_count": 1,
    "first_hit": {
        "file": "inc/aws/Aws/data/s3/2006-03-01/endpoint-tests-1.json.php",
        "line": 3,
        "snippet": "return [ 'testCases' => [ [ 'documentation' => 'region is not a valid DNS-suffix', 'expect' => [ 'error' => 'Invalid region: region was not a valid DNS name.', ], 'params' => [ 'Region' => 'a b', 'Use"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Spider Analyser – WordPress搜索引擎蜘蛛分析插件 (3k+ installs) Resolved 5mo ago
Slugspider-analyser
Patternhardcoded_ip_url
Kindbuiltin
Version2.1.3
Hit count3
First hit
File
spider_info.php
Line
8,889
Snippet
'bot_url' => 'http://195.37.190.77/',
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "spider-analyser",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "2.1.3",
    "hit_count": 3,
    "first_hit": {
        "file": "spider_info.php",
        "line": 8889,
        "snippet": "'bot_url' => 'http://195.37.190.77/',"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Live Chat with Messenger Customer Chat (3k+ installs) Resolved 5mo ago
Slugfb-messenger-live-chat
PatternPluginAUTH
Kindioc:code_pattern
Version1.5.0
Hit count1
First hit
File
fb-messenger-live-chat.php
Line
116
Snippet
$form = '<form class="ztb-register-form" target="_blank" method="POST" action="'.$domain_action.'/customer/access/PluginAuth?app=fbc&utm_source=wordpress.com&utm_medium=Facebook Live Chat&utm_campai
Explanation—
View raw JSON
{
    "slug": "fb-messenger-live-chat",
    "pattern": "PluginAUTH",
    "kind": "ioc:code_pattern",
    "version": "1.5.0",
    "hit_count": 1,
    "first_hit": {
        "file": "fb-messenger-live-chat.php",
        "line": 116,
        "snippet": "$form = '<form class=\"ztb-register-form\" target=\"_blank\" method=\"POST\" action=\"'.$domain_action.'/customer/access/PluginAuth?app=fbc&utm_source=wordpress.com&utm_medium=Facebook Live Chat&utm_campai"
    },
    "explanation": null
}
Critical code_pattern Gallery with thumbnail slider (3k+ installs) Resolved 5mo ago
Sluggallery-with-thumbnail-slider
Patternfilter_the_content_in_the_main_loop
Kindioc:code_pattern
Version8.1
Hit count2
First hit
File
gwts-slider.php
Line
6
Snippet
function gwts_gwl_filter_the_content_in_the_main_loop( $content ) {
Explanation—
View raw JSON
{
    "slug": "gallery-with-thumbnail-slider",
    "pattern": "filter_the_content_in_the_main_loop",
    "kind": "ioc:code_pattern",
    "version": "8.1",
    "hit_count": 2,
    "first_hit": {
        "file": "gwts-slider.php",
        "line": 6,
        "snippet": "function gwts_gwl_filter_the_content_in_the_main_loop( $content ) {"
    },
    "explanation": null
}
Critical code_pattern Kargo Takip, WooCommerce & Dokan Kargo Takip, SMS ve E-posta (2k+ installs) Resolved 5mo ago
Slugkargo-takip-turkiye
Patternhardcoded_ip_url
Kindbuiltin
Version0.2.4
Hit count1
First hit
File
config.php
Line
67
Snippet
"url" => "http://85.99.122.231/hareket.asp?har_kod=",
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "kargo-takip-turkiye",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "0.2.4",
    "hit_count": 1,
    "first_hit": {
        "file": "config.php",
        "line": 67,
        "snippet": "\"url\" => \"http://85.99.122.231/hareket.asp?har_kod=\","
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern ApplyOnline – Application Form Builder and Manager (2k+ installs) Resolved 5mo ago
Slugapply-online
Patternunserialize_after_remote_call
Kindbuiltin
Version2.6.8.1
Hit count1
First hit
File
class-addons-update.php
Line
153
Snippet
L149: $request = wp_remote_post($this->update_path, $params ); → L153: return @unserialize( $request['body'] );
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "apply-online",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "2.6.8.1",
    "hit_count": 1,
    "first_hit": {
        "file": "class-addons-update.php",
        "line": 153,
        "snippet": "L149: $request = wp_remote_post($this->update_path, $params );  \u2192  L153: return @unserialize( $request['body'] );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern YaySMTP – WP Mail SMTP with Email Logs, Tracking & Reports (10k+ installs) Resolved 5mo ago
Slugyaysmtp
PatternPluginAUTH
Kindioc:code_pattern
Version2.7.4
Hit count2
First hit
File
includes/Controller/ZohoServiceVendController.php
Line
41
Snippet
public static function getPluginAuthUrl() {
Explanation—
View raw JSON
{
    "slug": "yaysmtp",
    "pattern": "PluginAUTH",
    "kind": "ioc:code_pattern",
    "version": "2.7.4",
    "hit_count": 2,
    "first_hit": {
        "file": "includes/Controller/ZohoServiceVendController.php",
        "line": 41,
        "snippet": "public static function getPluginAuthUrl() {"
    },
    "explanation": null
}
Critical code_pattern Jetpack VaultPress (10k+ installs) Resolved 5mo ago
Slugvaultpress
Patternunserialize_after_remote_call
Kindbuiltin
Version4.0.7
Hit count1
First hit
File
vaultpress.php
Line
1,516
Snippet
L1512: $r = wp_remote_get( $url=sprintf( "%s://%s/%s?cidr_ranges=1", $protocol, $hostname, $pa → L1516: $data = @unserialize( wp_remote_retrieve_body( $r ) );
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "vaultpress",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "4.0.7",
    "hit_count": 1,
    "first_hit": {
        "file": "vaultpress.php",
        "line": 1516,
        "snippet": "L1512: $r = wp_remote_get( $url=sprintf( \"%s://%s/%s?cidr_ranges=1\", $protocol, $hostname, $pa  \u2192  L1516: $data = @unserialize( wp_remote_retrieve_body( $r ) );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern WSMS (formerly WP SMS) – SMS & MMS Notifications with OTP and 2FA for WooCommerce (7k+ installs) Resolved 5mo ago
Slugwp-sms
Patternhardcoded_ip_url
Kindbuiltin
Version7.2.4
Hit count7
First hit
File
includes/gateways/class-wpsms-gateway-onlinepanel.php
Line
9
Snippet
private $wsdl_link = "http://87.107.121.52/post/send.asmx?WSDL";
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "wp-sms",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "7.2.4",
    "hit_count": 7,
    "first_hit": {
        "file": "includes/gateways/class-wpsms-gateway-onlinepanel.php",
        "line": 9,
        "snippet": "private $wsdl_link = \"http://87.107.121.52/post/send.asmx?WSDL\";"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Security Ninja – WordPress Security & Firewall (7k+ installs) Resolved 5mo ago
Slugsecurity-ninja
Patternserialized_admin_role
Kindbuiltin
Version5.281
Hit count2
First hit
File
modules/events-logger/events-logger.php
Line
206
Snippet
'%s:13:"administrator"%',
Explanationplugin source contains `s:13:"administrator"` — the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand.
View raw JSON
{
    "slug": "security-ninja",
    "pattern": "serialized_admin_role",
    "kind": "builtin",
    "version": "5.281",
    "hit_count": 2,
    "first_hit": {
        "file": "modules/events-logger/events-logger.php",
        "line": 206,
        "snippet": "'%s:13:\"administrator\"%',"
    },
    "explanation": "plugin source contains `s:13:\"administrator\"` \u2014 the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand."
}
Critical code_pattern LearnPress – WordPress LMS Plugin for Create and Sell Online Courses (70k+ installs) Resolved 5mo ago
Sluglearnpress
Patternserialized_admin_role
Kindbuiltin
Version4.3.5
Hit count1
First hit
File
inc/admin/lp-admin-functions.php
Line
806
Snippet
'%' . $wpdb->esc_like( 's:13:"administrator"' ) . '%',
Explanationplugin source contains `s:13:"administrator"` — the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand.
View raw JSON
{
    "slug": "learnpress",
    "pattern": "serialized_admin_role",
    "kind": "builtin",
    "version": "4.3.5",
    "hit_count": 1,
    "first_hit": {
        "file": "inc/admin/lp-admin-functions.php",
        "line": 806,
        "snippet": "'%' . $wpdb->esc_like( 's:13:\"administrator\"' ) . '%',"
    },
    "explanation": "plugin source contains `s:13:\"administrator\"` \u2014 the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand."
}
Critical code_pattern افزونه پیامک ووکامرس | Persian WooCommerce SMS (40k+ installs) Resolved 5mo ago
Slugpersian-woocommerce-sms
Patternhardcoded_ip_url
Kindbuiltin
Version7.1.1
Hit count17
First hit
File
src/Gateways/PanelChi.php
Line
11
Snippet
public string $api_url = 'http://185.141.171.123/wbs/send.php?wsdl';
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "persian-woocommerce-sms",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "7.1.1",
    "hit_count": 17,
    "first_hit": {
        "file": "src/Gateways/PanelChi.php",
        "line": 11,
        "snippet": "public string $api_url = 'http://185.141.171.123/wbs/send.php?wsdl';"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern WP Database Backup – Unlimited Database & Files Backup by Backup for WP (20k+ installs) Resolved 5mo ago
Slugwp-database-backup
Patternwpconfig_creds_string
Kindbuiltin
Version7.10
Hit count10
First hit
File
includes/admin/class-wpdbbkp-restore.php
Line
180
Snippet
preg_match("/'DB_NAME',\s*'(.*)?'/", $config_file, $matches);
Explanationplugin source contains a literal string `"DB_NAME"` / `"DB_USER"` / `"DB_PASSWORD"` / `"DB_HOST"` — the credential constants are referenced by name only when something is parsing wp-config.php to harvest the database password, which legitimate plugins essentially never do. Signature of the June 2024 credential-stuffing payload that walked the filesystem looking for wp-config files and exfiltrated DB creds. wp-config itself uses these as constants (no surrounding quotes); plugin code that quotes them is the malicious shape.
View raw JSON
{
    "slug": "wp-database-backup",
    "pattern": "wpconfig_creds_string",
    "kind": "builtin",
    "version": "7.10",
    "hit_count": 10,
    "first_hit": {
        "file": "includes/admin/class-wpdbbkp-restore.php",
        "line": 180,
        "snippet": "preg_match(\"/'DB_NAME',\\s*'(.*)?'/\", $config_file, $matches);"
    },
    "explanation": "plugin source contains a literal string `\"DB_NAME\"` / `\"DB_USER\"` / `\"DB_PASSWORD\"` / `\"DB_HOST\"` \u2014 the credential constants are referenced by name only when something is parsing wp-config.php to harvest the database password, which legitimate plugins essentially never do. Signature of the June 2024 credential-stuffing payload that walked the filesystem looking for wp-config files and exfiltrated DB creds. wp-config itself uses these as constants (no surrounding quotes); plugin code that quotes them is the malicious shape."
}
Critical code_pattern NextScripts: Social Networks Auto-Poster (20k+ installs) Resolved 5mo ago
Slugsocial-networks-auto-poster-facebook-twitter-g
Patternhardcoded_ip_url
Kindbuiltin
Version4.4.7
Hit count1
First hit
File
inc/nxs_class_snap.php
Line
105
Snippet
nxs_cURLTest("http://45.79.4.45/", "HTTPS to NXSA", "NXS");
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "social-networks-auto-poster-facebook-twitter-g",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "4.4.7",
    "hit_count": 1,
    "first_hit": {
        "file": "inc/nxs_class_snap.php",
        "line": 105,
        "snippet": "nxs_cURLTest(\"http://45.79.4.45/\", \"HTTPS to NXSA\", \"NXS\");"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern FV Flowplayer Video Player (10k+ installs) Resolved 5mo ago
Slugfv-wordpress-flowplayer
Patternunserialize_after_remote_call
Kindbuiltin
Version7.5.49.7212
Hit count1
First hit
File
includes/fp-api-private.php
Line
397
Snippet
L387: $raw_response = wp_remote_post( $this->strPrivateAPI, $request ); → L397: $response = @unserialize( preg_replace( '~^/\*[\s\S]*?\*/\s+~', '', $raw_respons
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "fv-wordpress-flowplayer",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "7.5.49.7212",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/fp-api-private.php",
        "line": 397,
        "snippet": "L387: $raw_response = wp_remote_post( $this->strPrivateAPI, $request );  \u2192  L397: $response = @unserialize( preg_replace( '~^/\\*[\\s\\S]*?\\*/\\s+~', '', $raw_respons"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Slugduplicator
Patternserialized_admin_role
Kindbuiltin
Version1.5.16
Hit count1
First hit
File
installer/dup-installer/classes/config/class.conf.wp.php
Line
22
Snippet
const ADMIN_SERIALIZED_SECURITY_STRING = 'a:1:{s:13:"administrator";b:1;}';
Explanationplugin source contains `s:13:"administrator"` — the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand.
View raw JSON
{
    "slug": "duplicator",
    "pattern": "serialized_admin_role",
    "kind": "builtin",
    "version": "1.5.16",
    "hit_count": 1,
    "first_hit": {
        "file": "installer/dup-installer/classes/config/class.conf.wp.php",
        "line": 22,
        "snippet": "const ADMIN_SERIALIZED_SECURITY_STRING = 'a:1:{s:13:\"administrator\";b:1;}';"
    },
    "explanation": "plugin source contains `s:13:\"administrator\"` \u2014 the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand."
}
Critical code_pattern GTM4WP – A Google Tag Manager (GTM) plugin for WordPress (700k+ installs) Resolved 5mo ago
Slugduracelltomi-google-tag-manager
Patternhardcoded_ip_url
Kindbuiltin
Version1.22.3
Hit count38
First hit
File
integration/whichbrowser/data/profiles.php
Line
647
Snippet
'http://112.74.195.169/upload/xmlfiles/STUDIO_X8_HD.XML' => [ 'BLU', 'Studio X8 HD', 'Android', DeviceType::MOBILE ],
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "duracelltomi-google-tag-manager",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "1.22.3",
    "hit_count": 38,
    "first_hit": {
        "file": "integration/whichbrowser/data/profiles.php",
        "line": 647,
        "snippet": "'http://112.74.195.169/upload/xmlfiles/STUDIO_X8_HD.XML'                                              => [ 'BLU', 'Studio X8 HD', 'Android', DeviceType::MOBILE ],"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern Flexible SSL for CloudFlare (100k+ installs) Resolved 5mo ago
Slugcloudflare-flexible-ssl
PatternPluginAUTH
Kindioc:code_pattern
Version1.3.1
Hit count2
First hit
File
plugin.php
Line
4
Snippet
* Plugin URI: https://icwp.io/cloudflaresslpluginauthor
Explanation—
View raw JSON
{
    "slug": "cloudflare-flexible-ssl",
    "pattern": "PluginAUTH",
    "kind": "ioc:code_pattern",
    "version": "1.3.1",
    "hit_count": 2,
    "first_hit": {
        "file": "plugin.php",
        "line": 4,
        "snippet": "* Plugin URI: https://icwp.io/cloudflaresslpluginauthor"
    },
    "explanation": null
}
Critical code_pattern NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall (100k+ installs) Resolved 5mo ago
Slugninjafirewall
Patternhardcoded_ip_url
Kindbuiltin
Version4.8.5
Hit count1
First hit
File
lib/help.php
Line
250
Snippet
<p><strong>' . __('Block HTTP requests with an IP in the <code>HTTP_HOST</code> header', 'ninjafirewall'). '</strong><br />' . sprintf( __('This option will reject any request using an IP instead of
Explanationplugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) — legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths.
View raw JSON
{
    "slug": "ninjafirewall",
    "pattern": "hardcoded_ip_url",
    "kind": "builtin",
    "version": "4.8.5",
    "hit_count": 1,
    "first_hit": {
        "file": "lib/help.php",
        "line": 250,
        "snippet": "<p><strong>' . __('Block HTTP requests with an IP in the <code>HTTP_HOST</code> header', 'ninjafirewall'). '</strong><br />' . sprintf( __('This option will reject any request using an IP instead of"
    },
    "explanation": "plugin source hardcodes a raw IPv4 URL (e.g. `https://94.156.79.8/...`) \u2014 legitimate plugins use DNS hostnames because IPs change. Hardcoded IPs in plugin code are almost always either dev leftovers or attacker C2 infrastructure. The June 2024 social-warfare keylogger (audit #14) used `https://94.156.79.8/sc-top.js` for the JS payload host, `/AddSites` for victim registration, `/CMSUsers` for filesystem-recon exfil. Operator infrastructure on raw IPs avoids domain registration / RDAP detection paths. Post-filtered to skip RFC1918/loopback/link-local ranges and `vendor/`/`tests/` paths."
}
Critical code_pattern NinjaFirewall (WP Edition) – Advanced Security Plugin and Firewall (100k+ installs) Resolved 5mo ago
Slugninjafirewall
Patternserialized_admin_role
Kindbuiltin
Version4.8.5
Hit count1
First hit
File
lib/utils.php
Line
1,319
Snippet
if ( strpos( $value, 's:13:"administrator"') === FALSE &&
Explanationplugin source contains `s:13:"administrator"` — the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand.
View raw JSON
{
    "slug": "ninjafirewall",
    "pattern": "serialized_admin_role",
    "kind": "builtin",
    "version": "4.8.5",
    "hit_count": 1,
    "first_hit": {
        "file": "lib/utils.php",
        "line": 1319,
        "snippet": "if ( strpos( $value, 's:13:\"administrator\"') === FALSE &&"
    },
    "explanation": "plugin source contains `s:13:\"administrator\"` \u2014 the PHP-serialized representation of the `administrator` role meta value. Used to bypass `wp_insert_user()` by writing directly to `wp_usermeta` with a hand-crafted capabilities string. Near-zero FP because legit code uses `WP_User::set_role()` instead of building the serialized form by hand."
}
Critical code_pattern Starter Sites & Templates by Neve (100k+ installs) Resolved 5mo ago
Slugtemplates-patterns-collection
Patternunserialize_after_remote_call
Kindbuiltin
Version1.2.27
Hit count1
First hit
File
includes/TI_Beaver.php
Line
167
Snippet
L148: $response = wp_remote_get( esc_url_raw( $url ) ); → L167: if ( @unserialize( $serialized_string ) !== true && preg_match( '/^[aOs]:/', $serialized
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "templates-patterns-collection",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "1.2.27",
    "hit_count": 1,
    "first_hit": {
        "file": "includes/TI_Beaver.php",
        "line": 167,
        "snippet": "L148: $response = wp_remote_get( esc_url_raw( $url ) );  \u2192  L167: if ( @unserialize( $serialized_string ) !== true && preg_match( '/^[aOs]:/', $serialized"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Slugchatbot
Patternunserialize_after_remote_call
Kindbuiltin
Version8.2.4
Hit count2
First hit
File
includes/integration/openai/plugin-upgrader/classes/plugin-upgrader.php
Line
190
Snippet
L185: $request = wp_remote_post($this->update_path, $params ); → L190: return @unserialize( $request['body'] );
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "chatbot",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "8.2.4",
    "hit_count": 2,
    "first_hit": {
        "file": "includes/integration/openai/plugin-upgrader/classes/plugin-upgrader.php",
        "line": 190,
        "snippet": "L185: $request = wp_remote_post($this->update_path, $params );  \u2192  L190: return @unserialize( $request['body'] );"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_pattern YARPP – Yet Another Related Posts Plugin (100k+ installs) Benign 5mo ago
Slugyet-another-related-posts-plugin
Patternunserialize_after_remote_call
Kindbuiltin
Version5.30.11
Hit count1
First hit
File
classes/YARPP_Core.php
Line
2,112
Snippet
L2105: $remote = wp_remote_post( "https://yarpp.org/checkversion.php?format=php&version={$vers → L2112: if ( $result = @unserialize( $remote['body'] ) ) {
Explanationa remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file — classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised.
View raw JSON
{
    "slug": "yet-another-related-posts-plugin",
    "pattern": "unserialize_after_remote_call",
    "kind": "builtin",
    "version": "5.30.11",
    "hit_count": 1,
    "first_hit": {
        "file": "classes/YARPP_Core.php",
        "line": 2112,
        "snippet": "L2105: $remote  = wp_remote_post( \"https://yarpp.org/checkversion.php?format=php&version={$vers  \u2192  L2112: if ( $result = @unserialize( $remote['body'] ) ) {"
    },
    "explanation": "a remote HTTP fetch (`wp_remote_*` / `curl_exec`) is followed by `@unserialize` within the same file \u2014 classic PHP Object Injection C2 gadget. The error-suppressed form is the tell: legit code wants to know when deserialize fails; attackers suppress so malformed gadgets do not leak. A real finding regardless of author intent: any plugin that deserializes remote responses without validation is a latent RCE chain if the remote endpoint is ever compromised."
}
Critical code_scan_delta Jetpack VaultPress (10k+ installs) Resolved 5mo ago
Slugvaultpress
Previous version4.0.7
Current version4.0.7
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinvaultpress.php1,516L1512: $r = wp_remote_get( $url=sprintf( "%s://%s/%s?cidr_ranges=1", $protocol, $hostname, $pa → L1516: $data = @unserialize( wp_remote_retrieve_body( $r ) );high
New finding count1
View raw JSON
{
    "slug": "vaultpress",
    "previous_version": "4.0.7",
    "current_version": "4.0.7",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "vaultpress.php",
            "line": 1516,
            "snippet": "L1512: $r = wp_remote_get( $url=sprintf( \"%s://%s/%s?cidr_ranges=1\", $protocol, $hostname, $pa  \u2192  L1516: $data = @unserialize( wp_remote_retrieve_body( $r ) );",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta YaySMTP – WP Mail SMTP with Email Logs, Tracking & Reports (10k+ installs) Resolved 5mo ago
Slugyaysmtp
Previous version2.7.4
Current version2.7.4
New findings
PatternKindFileLineSnippetConfidence
PluginAUTHioc:code_patternincludes/Controller/ZohoServiceVendController.php41public static function getPluginAuthUrl() {high
PluginAUTHioc:code_patternincludes/Controller/ZohoServiceVendController.php111$params['redirect_uri'] = self::getPluginAuthUrl();high
New finding count2
View raw JSON
{
    "slug": "yaysmtp",
    "previous_version": "2.7.4",
    "current_version": "2.7.4",
    "new_findings": [
        {
            "pattern": "PluginAUTH",
            "kind": "ioc:code_pattern",
            "file": "includes/Controller/ZohoServiceVendController.php",
            "line": 41,
            "snippet": "public static function getPluginAuthUrl() {",
            "confidence": "high"
        },
        {
            "pattern": "PluginAUTH",
            "kind": "ioc:code_pattern",
            "file": "includes/Controller/ZohoServiceVendController.php",
            "line": 111,
            "snippet": "$params['redirect_uri']  = self::getPluginAuthUrl();",
            "confidence": "high"
        }
    ],
    "new_finding_count": 2
}
Critical code_scan_delta Slider by 10Web – Responsive Image Slider (10k+ installs) Resolved 5mo ago
Slugslider-wd
Previous version1.2.62
Current version1.2.62
New findings
PatternKindFileLineSnippetConfidenceDetails
remote_enqueuebuiltinslider-wd.php886wp_register_script($this->prefix . '_youtube', 'https://www.youtube.com/iframe_api');medium
Url
https://www.youtube.com/iframe_api
Url host
www.youtube.com
New finding count1
Serial offender noteSeverity bumped high→critical: author 10web has 6 prior security-issue closures on wp.org.
View raw JSON
{
    "slug": "slider-wd",
    "previous_version": "1.2.62",
    "current_version": "1.2.62",
    "new_findings": [
        {
            "pattern": "remote_enqueue",
            "kind": "builtin",
            "file": "slider-wd.php",
            "line": 886,
            "snippet": "wp_register_script($this->prefix . '_youtube', 'https://www.youtube.com/iframe_api');",
            "confidence": "medium",
            "details": {
                "url": "https://www.youtube.com/iframe_api",
                "url_host": "www.youtube.com"
            }
        }
    ],
    "new_finding_count": 1,
    "serial_offender_note": "Severity bumped high\u2192critical: author 10web has 6 prior security-issue closures on wp.org."
}
Critical code_scan_delta FV Flowplayer Video Player (10k+ installs) Resolved 5mo ago
Slugfv-wordpress-flowplayer
Previous version7.5.49.7212
Current version7.5.49.7212
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinincludes/fp-api-private.php397L387: $raw_response = wp_remote_post( $this->strPrivateAPI, $request ); → L397: $response = @unserialize( preg_replace( '~^/\*[\s\S]*?\*/\s+~', '', $raw_responshigh
New finding count1
View raw JSON
{
    "slug": "fv-wordpress-flowplayer",
    "previous_version": "7.5.49.7212",
    "current_version": "7.5.49.7212",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/fp-api-private.php",
            "line": 397,
            "snippet": "L387: $raw_response = wp_remote_post( $this->strPrivateAPI, $request );  \u2192  L397: $response = @unserialize( preg_replace( '~^/\\*[\\s\\S]*?\\*/\\s+~', '', $raw_respons",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta NextScripts: Social Networks Auto-Poster (20k+ installs) Resolved 5mo ago
Slugsocial-networks-auto-poster-facebook-twitter-g
Previous version4.4.7
Current version4.4.7
New findings
PatternKindFileLineSnippetConfidence
hardcoded_ip_urlbuiltininc/nxs_class_snap.php105nxs_cURLTest("http://45.79.4.45/", "HTTPS to NXSA", "NXS");high
New finding count1
View raw JSON
{
    "slug": "social-networks-auto-poster-facebook-twitter-g",
    "previous_version": "4.4.7",
    "current_version": "4.4.7",
    "new_findings": [
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "inc/nxs_class_snap.php",
            "line": 105,
            "snippet": "nxs_cURLTest(\"http://45.79.4.45/\", \"HTTPS to NXSA\", \"NXS\");",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta WP Database Backup – Unlimited Database & Files Backup by Backup for WP (20k+ installs) Resolved 5mo ago
Slugwp-database-backup
Previous version7.10
Current version7.10
New findings
PatternKindFileLineSnippetConfidence
wpconfig_creds_stringbuiltinincludes/admin/class-wpdbbkp-restore.php180preg_match("/'DB_NAME',\s*'(.*)?'/", $config_file, $matches);high
wpconfig_creds_stringbuiltinincludes/admin/class-wpdbbkp-restore.php193preg_match("/'DB_NAME',\s*'(.*)?'/", $config_file, $matches);high
wpconfig_creds_stringbuiltinincludes/admin/class-wpdbbkp-restore.php196preg_match("/'DB_USER',\s*'(.*)?'/", $config_file, $matches);high
wpconfig_creds_stringbuiltinincludes/admin/class-wpdbbkp-restore.php199preg_match("/'DB_PASSWORD',\s*'(.*)?'/", $config_file, $matches);high
wpconfig_creds_stringbuiltinincludes/admin/class-wpdbbkp-restore.php202preg_match("/'DB_HOST',\s*'(.*)?'/", $config_file, $matches);high
wpconfig_creds_stringbuiltinincludes/admin/class-wpdb-admin.php3,096preg_match( "/'DB_NAME',\s*'(.*)?'/", $config_file, $matches );high
wpconfig_creds_stringbuiltinincludes/admin/class-wpdb-admin.php3,099preg_match( "/'DB_USER',\s*'(.*)?'/", $config_file, $matches );high
wpconfig_creds_stringbuiltinincludes/admin/class-wpdb-admin.php3,102preg_match( "/'DB_PASSWORD',\s*'(.*)?'/", $config_file, $matches );high
wpconfig_creds_stringbuiltinincludes/admin/class-wpdb-admin.php3,105preg_match( "/'DB_HOST',\s*'(.*)?'/", $config_file, $matches );high
wpconfig_creds_stringbuiltinincludes/admin/class-wpdb-admin.php3,122preg_match( "/'DB_NAME',\s*'(.*)?'/", $config_file, $matches );high
New finding count10
View raw JSON
{
    "slug": "wp-database-backup",
    "previous_version": "7.10",
    "current_version": "7.10",
    "new_findings": [
        {
            "pattern": "wpconfig_creds_string",
            "kind": "builtin",
            "file": "includes/admin/class-wpdbbkp-restore.php",
            "line": 180,
            "snippet": "preg_match(\"/'DB_NAME',\\s*'(.*)?'/\", $config_file, $matches);",
            "confidence": "high"
        },
        {
            "pattern": "wpconfig_creds_string",
            "kind": "builtin",
            "file": "includes/admin/class-wpdbbkp-restore.php",
            "line": 193,
            "snippet": "preg_match(\"/'DB_NAME',\\s*'(.*)?'/\", $config_file, $matches);",
            "confidence": "high"
        },
        {
            "pattern": "wpconfig_creds_string",
            "kind": "builtin",
            "file": "includes/admin/class-wpdbbkp-restore.php",
            "line": 196,
            "snippet": "preg_match(\"/'DB_USER',\\s*'(.*)?'/\", $config_file, $matches);",
            "confidence": "high"
        },
        {
            "pattern": "wpconfig_creds_string",
            "kind": "builtin",
            "file": "includes/admin/class-wpdbbkp-restore.php",
            "line": 199,
            "snippet": "preg_match(\"/'DB_PASSWORD',\\s*'(.*)?'/\", $config_file, $matches);",
            "confidence": "high"
        },
        {
            "pattern": "wpconfig_creds_string",
            "kind": "builtin",
            "file": "includes/admin/class-wpdbbkp-restore.php",
            "line": 202,
            "snippet": "preg_match(\"/'DB_HOST',\\s*'(.*)?'/\", $config_file, $matches);",
            "confidence": "high"
        },
        {
            "pattern": "wpconfig_creds_string",
            "kind": "builtin",
            "file": "includes/admin/class-wpdb-admin.php",
            "line": 3096,
            "snippet": "preg_match( \"/'DB_NAME',\\s*'(.*)?'/\", $config_file, $matches );",
            "confidence": "high"
        },
        {
            "pattern": "wpconfig_creds_string",
            "kind": "builtin",
            "file": "includes/admin/class-wpdb-admin.php",
            "line": 3099,
            "snippet": "preg_match( \"/'DB_USER',\\s*'(.*)?'/\", $config_file, $matches );",
            "confidence": "high"
        },
        {
            "pattern": "wpconfig_creds_string",
            "kind": "builtin",
            "file": "includes/admin/class-wpdb-admin.php",
            "line": 3102,
            "snippet": "preg_match( \"/'DB_PASSWORD',\\s*'(.*)?'/\", $config_file, $matches );",
            "confidence": "high"
        },
        {
            "pattern": "wpconfig_creds_string",
            "kind": "builtin",
            "file": "includes/admin/class-wpdb-admin.php",
            "line": 3105,
            "snippet": "preg_match( \"/'DB_HOST',\\s*'(.*)?'/\", $config_file, $matches );",
            "confidence": "high"
        },
        {
            "pattern": "wpconfig_creds_string",
            "kind": "builtin",
            "file": "includes/admin/class-wpdb-admin.php",
            "line": 3122,
            "snippet": "preg_match( \"/'DB_NAME',\\s*'(.*)?'/\", $config_file, $matches );",
            "confidence": "high"
        }
    ],
    "new_finding_count": 10
}
Critical code_scan_delta Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder (30k+ installs) Resolved 5mo ago
Slugform-maker
Previous version1.15.42
Current version1.15.43
New findings
PatternKindFileLineSnippetConfidenceDetails
remote_enqueuebuiltinform-maker.php1,161wp_register_script($this->handle_prefix . '-g-recaptcha', 'https://www.google.com/recaptcha/api.js?hl='.$lng.'&onload=fmRecaptchaInit&render=explicit');medium
Url
https://www.google.com/recaptcha/api.js?hl=
Url host
www.google.com
remote_enqueuebuiltinform-maker.php1,163wp_register_script($this->handle_prefix . '-g-recaptcha-v3', 'https://www.google.com/recaptcha/api.js?hl='.$lng.'&onload=fmRecaptchaInit&render=' . $fm_settings['public_key']);medium
Url
https://www.google.com/recaptcha/api.js?hl=
Url host
www.google.com
New finding count2
Serial offender noteSeverity bumped high→critical: author 10web has 6 prior security-issue closures on wp.org.
View raw JSON
{
    "slug": "form-maker",
    "previous_version": "1.15.42",
    "current_version": "1.15.43",
    "new_findings": [
        {
            "pattern": "remote_enqueue",
            "kind": "builtin",
            "file": "form-maker.php",
            "line": 1161,
            "snippet": "wp_register_script($this->handle_prefix . '-g-recaptcha', 'https://www.google.com/recaptcha/api.js?hl='.$lng.'&onload=fmRecaptchaInit&render=explicit');",
            "confidence": "medium",
            "details": {
                "url": "https://www.google.com/recaptcha/api.js?hl=",
                "url_host": "www.google.com"
            }
        },
        {
            "pattern": "remote_enqueue",
            "kind": "builtin",
            "file": "form-maker.php",
            "line": 1163,
            "snippet": "wp_register_script($this->handle_prefix . '-g-recaptcha-v3', 'https://www.google.com/recaptcha/api.js?hl='.$lng.'&onload=fmRecaptchaInit&render=' . $fm_settings['public_key']);",
            "confidence": "medium",
            "details": {
                "url": "https://www.google.com/recaptcha/api.js?hl=",
                "url_host": "www.google.com"
            }
        }
    ],
    "new_finding_count": 2,
    "serial_offender_note": "Severity bumped high\u2192critical: author 10web has 6 prior security-issue closures on wp.org."
}
Critical code_scan_delta افزونه پیامک ووکامرس | Persian WooCommerce SMS (40k+ installs) Resolved 5mo ago
Slugpersian-woocommerce-sms
Previous version7.1.1
Current version7.1.1
New findings
PatternKindFileLineSnippetConfidence
hardcoded_ip_urlbuiltinsrc/Gateways/PanelChi.php11public string $api_url = 'http://185.141.171.123/wbs/send.php?wsdl';high
hardcoded_ip_urlbuiltinsrc/Gateways/IdehPayam.php34$soap = new SoapClient( "http://185.112.33.61/webservice/send.php?wsdl" );high
hardcoded_ip_urlbuiltinsrc/Gateways/ChaparPanel.php33$client = new SoapClient( "http://87.107.121.52/post/send.asmx?wsdl" );high
hardcoded_ip_urlbuiltinsrc/Gateways/RazPayamak.php33$client = new SoapClient( "http://37.228.138.118/post/send.asmx?wsdl" );high
hardcoded_ip_urlbuiltinsrc/Gateways/NiazPardazCOM.php34$client = new SoapClient( "http://37.228.138.118/post/send.asmx?wsdl" );high
hardcoded_ip_urlbuiltinsrc/Gateways/LoginPanel.php33$client = new SoapClient( "http://87.107.121.52/post/send.asmx?wsdl" );high
hardcoded_ip_urlbuiltinsrc/Gateways/YektaTech.php34$client = new SoapClient( "http://37.228.138.118/post/send.asmx?wsdl" );high
hardcoded_ip_urlbuiltinsrc/Gateways/ParsianSMS.php38$remote = wp_remote_get( 'http://185.4.31.182/class/sms/webservice/send_url.php?' . $content );high
hardcoded_ip_urlbuiltinsrc/Gateways/SMSMeli.php35$client = new SoapClient( "http://37.228.138.118/post/send.asmx?wsdl" );high
hardcoded_ip_urlbuiltinsrc/Gateways/MehrPanel.php33$client = new SoapClient( "http://87.107.121.52/post/send.asmx?wsdl" );high
hardcoded_ip_urlbuiltinsrc/Gateways/SMSPishgaman.php66$client = new nusoap_client( 'http://82.99.216.45/services/?wsdl', true );high
hardcoded_ip_urlbuiltinsrc/Gateways/SMSMelli.php40$remote = wp_remote_get( 'http://185.4.31.182/class/sms/webservice/send_url.php?' . $content );high
hardcoded_ip_urlbuiltinsrc/Gateways/GamaPayamak.php34$client = new SoapClient( "http://37.228.138.118/post/send.asmx?wsdl" );high
hardcoded_ip_urlbuiltinsrc/Gateways/ParandSMS.php32$client = new SoapClient( "http://87.107.121.52/post/send.asmx?wsdl" );high
hardcoded_ip_urlbuiltinsrc/Gateways/SMSBefrest.php34$client = new SoapClient( "http://87.107.121.52/post/send.asmx?wsdl" );high
New finding count17
View raw JSON
{
    "slug": "persian-woocommerce-sms",
    "previous_version": "7.1.1",
    "current_version": "7.1.1",
    "new_findings": [
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/PanelChi.php",
            "line": 11,
            "snippet": "public string $api_url = 'http://185.141.171.123/wbs/send.php?wsdl';",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/IdehPayam.php",
            "line": 34,
            "snippet": "$soap = new SoapClient( \"http://185.112.33.61/webservice/send.php?wsdl\" );",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/ChaparPanel.php",
            "line": 33,
            "snippet": "$client       = new SoapClient( \"http://87.107.121.52/post/send.asmx?wsdl\" );",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/RazPayamak.php",
            "line": 33,
            "snippet": "$client       = new SoapClient( \"http://37.228.138.118/post/send.asmx?wsdl\" );",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/NiazPardazCOM.php",
            "line": 34,
            "snippet": "$client       = new SoapClient( \"http://37.228.138.118/post/send.asmx?wsdl\" );",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/LoginPanel.php",
            "line": 33,
            "snippet": "$client       = new SoapClient( \"http://87.107.121.52/post/send.asmx?wsdl\" );",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/YektaTech.php",
            "line": 34,
            "snippet": "$client       = new SoapClient( \"http://37.228.138.118/post/send.asmx?wsdl\" );",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/ParsianSMS.php",
            "line": 38,
            "snippet": "$remote = wp_remote_get( 'http://185.4.31.182/class/sms/webservice/send_url.php?' . $content );",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/SMSMeli.php",
            "line": 35,
            "snippet": "$client       = new SoapClient( \"http://37.228.138.118/post/send.asmx?wsdl\" );",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/MehrPanel.php",
            "line": 33,
            "snippet": "$client = new SoapClient( \"http://87.107.121.52/post/send.asmx?wsdl\" );",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/SMSPishgaman.php",
            "line": 66,
            "snippet": "$client                   = new nusoap_client( 'http://82.99.216.45/services/?wsdl', true );",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/SMSMelli.php",
            "line": 40,
            "snippet": "$remote = wp_remote_get( 'http://185.4.31.182/class/sms/webservice/send_url.php?' . $content );",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/GamaPayamak.php",
            "line": 34,
            "snippet": "$client       = new SoapClient( \"http://37.228.138.118/post/send.asmx?wsdl\" );",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/ParandSMS.php",
            "line": 32,
            "snippet": "$client = new SoapClient( \"http://87.107.121.52/post/send.asmx?wsdl\" );",
            "confidence": "high"
        },
        {
            "pattern": "hardcoded_ip_url",
            "kind": "builtin",
            "file": "src/Gateways/SMSBefrest.php",
            "line": 34,
            "snippet": "$client = new SoapClient( \"http://87.107.121.52/post/send.asmx?wsdl\" );",
            "confidence": "high"
        }
    ],
    "new_finding_count": 17
}
Critical code_scan_delta LearnPress – WordPress LMS Plugin for Create and Sell Online Courses (70k+ installs) Resolved 5mo ago
Sluglearnpress
Previous version4.3.5
Current version4.3.5
New findings
PatternKindFileLineSnippetConfidence
serialized_admin_rolebuiltininc/admin/lp-admin-functions.php806'%' . $wpdb->esc_like( 's:13:"administrator"' ) . '%',high
New finding count1
View raw JSON
{
    "slug": "learnpress",
    "previous_version": "4.3.5",
    "current_version": "4.3.5",
    "new_findings": [
        {
            "pattern": "serialized_admin_role",
            "kind": "builtin",
            "file": "inc/admin/lp-admin-functions.php",
            "line": 806,
            "snippet": "'%' . $wpdb->esc_like( 's:13:\"administrator\"' ) . '%',",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta Starter Sites & Templates by Neve (100k+ installs) Resolved 5mo ago
Slugtemplates-patterns-collection
Previous version1.2.27
Current version1.2.27
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinincludes/TI_Beaver.php167L148: $response = wp_remote_get( esc_url_raw( $url ) ); → L167: if ( @unserialize( $serialized_string ) !== true && preg_match( '/^[aOs]:/', $serializedhigh
New finding count1
View raw JSON
{
    "slug": "templates-patterns-collection",
    "previous_version": "1.2.27",
    "current_version": "1.2.27",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "includes/TI_Beaver.php",
            "line": 167,
            "snippet": "L148: $response = wp_remote_get( esc_url_raw( $url ) );  \u2192  L167: if ( @unserialize( $serialized_string ) !== true && preg_match( '/^[aOs]:/', $serialized",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}
Critical code_scan_delta YARPP – Yet Another Related Posts Plugin (100k+ installs) Benign 5mo ago
Slugyet-another-related-posts-plugin
Previous version5.30.11
Current version5.30.11
New findings
PatternKindFileLineSnippetConfidence
unserialize_after_remote_callbuiltinclasses/YARPP_Core.php2,112L2105: $remote = wp_remote_post( "https://yarpp.org/checkversion.php?format=php&version={$vers → L2112: if ( $result = @unserialize( $remote['body'] ) ) {high
New finding count1
View raw JSON
{
    "slug": "yet-another-related-posts-plugin",
    "previous_version": "5.30.11",
    "current_version": "5.30.11",
    "new_findings": [
        {
            "pattern": "unserialize_after_remote_call",
            "kind": "builtin",
            "file": "classes/YARPP_Core.php",
            "line": 2112,
            "snippet": "L2105: $remote  = wp_remote_post( \"https://yarpp.org/checkversion.php?format=php&version={$vers  \u2192  L2112: if ( $result = @unserialize( $remote['body'] ) ) {",
            "confidence": "high"
        }
    ],
    "new_finding_count": 1
}