Issue 147: Vulnerabilities in SEOPress plugin and Steam portal, results from an application security survey
Brief
This week, we have the recent API vulnerabilities in the SEOPress WordPress plugin and the Valve Software Steam portal, the results from a Dark Reading survey into application security, and details of the upcoming OpenAPI Initiative’s (OAI) API Specifications Conference.
Vulnerability: XSS and REST API vulnerability in SEOPress
On July 29, 2021, the Wordfence Threat Intelligence team initiated the responsible disclosure process for a vulnerability that they discovered in SEOPress , a WordPress plugin installed on over 100 000 sites.
The researchers found that a REST API endpoint that the SEOPress plugin exposed for adding metadata to a post also allowed injecting arbitrary HTML payloads into the SEO fields of WordPress posts.
