
Episode 55: Popping WordPress Plugins - Methodology Braindump
Critical Thinking - Bug Bounty Podcast
00:00
Handling User Input in WordPress Plugins
This chapter explores different methods of handling user input in WordPress plugins, including traditional methods like dollar sign underscore get and dollar sign underscore post, as well as other functions like get query var and filter input. The speakers discuss the challenges of automating WordPress vulnerability analysis and suggest implementing a globally applied coding standard. They also delve into the lack of access control and CSRF protection in WordPress Ajax functions.
Transcript
Play full episode