WPDeeply Research
15 published guides
WordPress Importer — Arbitrary Post Creation
The official WordPress Importer accepts a structured file and creates content from it. WPDeeply’s 2021 disclosure examined what happens when the file is not trustworthy.
Abandoned Cart Lite for WooCommerce before 5.8.2 — SQL Injection
Unsanitised cart parameters in Abandoned Cart Lite for WooCommerce exposed stored customer data to unauthenticated extraction. Fixed in 5.8.3.
Loginizer before 1.6.4 — Unauthenticated SQL Injection
An unauthenticated SQL injection in Loginizer’s brute-force protection, reachable from any WordPress login form. Fixed in 1.6.4 — and pushed to over a million sites by a rare…
Ninja Forms before 3.4.27.1 — Simple CSRF to RCE
A missing request-origin check in Ninja Forms let one crafted link, clicked by a logged-in administrator, escalate into code execution. Fixed in 3.4.27.1.
WooCommerce before 4.1.0 — Remote Code Execution
A security fix that reached millions of stores through a changelog line reading like routine maintenance — and the ecosystem of plugins that copied the original code.