_WPScan_ Profile Banner
WPScan - WordPress Security Profile
WPScan - WordPress Security

@_WPScan_

Followers
8K
Following
1K
Media
108
Statuses
4K

With our very own WordPress vulnerability database, WPScan is the leading software for WordPress security scanning.

Global
Joined July 2012
Don't wanna be here? Send us removal request.
@_WPScan_
WPScan - WordPress Security
1 year
Our researchers found a Pre-Auth Object Injection vulnerability in the SEOPress plugin (300k+ active installs). It was fixed in the recent 7.9 update. Make sure to update now! #wordpress #security.
Tweet card summary image
wpscan.com
During a routine audit of various WordPress plugins, we identified a few issues in SEOPress (300k+ active installs). More specifically, we discovered an authentication bug which could allow attacke…
0
1
5
@_WPScan_
WPScan - WordPress Security
2 years
Thank you WPScan'ers for your trust! We're sending holiday cheer to you and your family. ☃️
Tweet media one
1
0
1
@_WPScan_
WPScan - WordPress Security
2 years
Our researchers found a Pre-Auth Stored XSS vulnerability in the WP Go Maps plugin (formerly known as WP Google Maps, 400k+ active installs). It was fixed in the recent 9.0.28 update. Make sure to update now!. #wordpress #security.
Tweet card summary image
wpscan.com
During an analysis of the WP Go Maps plugin (formerly WP Google Maps), we discovered a pretty serious Stored XSS vulnerability that can be exploited by any attackers, regardless of whether they hav…
0
1
4
@_WPScan_
WPScan - WordPress Security
2 years
Our researchers found a Pre-Auth Stored XSS vulnerability in the Popup Builder plugin (200k+ active installs). It was fixed in the recent 4.2.3 update. Make sure to update now!. #wordpress #security.
Tweet card summary image
wpscan.com
During an analysis of the Popup Builder plugin, we discovered a pretty serious Stored XSS vulnerability that can be exploited by any attackers, regardless of whether they have an account on the sit…
2
3
5
@_WPScan_
WPScan - WordPress Security
2 years
Our researchers found a serious SQL Injection vulnerability in the WP Fastest Cache plugin. It was fixed in the recent 1.2.2 update. Make sure to update now!. #wordpress #security.
Tweet card summary image
wpscan.com
During an internal review of the WP Fastest Cache plugin, the WPScan team discovered a serious SQL injection vulnerability. This vulnerability may allow unauthenticated attackers to read the full c…
0
1
6
@_WPScan_
WPScan - WordPress Security
2 years
URGENT: Active Hacking Campaign Targeting WordPress Plugin 'Royal Elementor Addons' (200,000+ active installs). Update to 1.3.79 ASAP! . For more info:. #wordpress #security.
Tweet card summary image
wpscan.com
During an investigation of a series of website being actively compromised we noticed the constant presence of the Royal Elementor Addons and Templates plugin installed. And all sites had at least o…
0
0
2
@_WPScan_
WPScan - WordPress Security
2 years
Our researchers found a RCE gadget chain in WordPress Core. Fortunately, it was fixed on the recent 6.3.2 update. Here's how it worked:. #wordpress #security.
Tweet card summary image
wpscan.com
During a recent team gathering in Belgium, we had an impromptu Capture The Flag game that included a challenge with an SQL Injection vulnerability occurring inside an INSERT statement, meaning atta…
2
2
8
@_WPScan_
WPScan - WordPress Security
2 years
URGENT: Active Hacking Campaign Targeting #WordPress Plugin 'Ultimate Member' (200,000+ active installs). We strongly recommend disabling this plugin immediately until a patch is released that fixes the vulnerability. For more info:
2
11
19
@_WPScan_
WPScan - WordPress Security
2 years
Are you attending WordCamp Europe in Athens? We'd love to see you and talk security! Please come find the WPScan team at the Jetpack booth at WCEU. #WCEU #WordPress #security
Tweet media one
1
1
1
@_WPScan_
WPScan - WordPress Security
2 years
WordPress VIP Integrates WPScan to Flag Potential Vulnerabilities with Major Sites Before They Go to Production.
1
1
5
@_WPScan_
WPScan - WordPress Security
2 years
Uncovering a PHAR Deserialization Vulnerability in WP Meta SEO and Escalating to RCE.
0
0
2
@_WPScan_
WPScan - WordPress Security
2 years
WP Engine’s Security Team Creates Custom Workflow with WPScan to Protect Clients
1
0
0
@_WPScan_
WPScan - WordPress Security
2 years
What is a brute force attack?.
0
0
0
@_WPScan_
WPScan - WordPress Security
2 years
1
0
1
@_WPScan_
WPScan - WordPress Security
3 years
WordPress Black Box Testing Basics.
0
2
3
@_WPScan_
WPScan - WordPress Security
3 years
Fake plugin affecting WordPress sites.
0
3
4
@_WPScan_
WPScan - WordPress Security
3 years
0
0
0