
More improvements to Attack Surface Custom Policies
Tl;dr We’ve made a few improvements to Attack Surface Custom Policies, such as viewing alerts more easily and deleting custom policies. We’ve also made a …

Detectify Admin
![[Alert] Stored XSS in WordPress Plugin Jetpack](/_next/image/?url=https%3A%2F%2Fblog-detectify-api.stage.io-ext.se%2Fapp%2Fuploads%2F2022%2F11%2Fwordpress-logo-notext-rgb-1.png&w=3840&q=75)
Sucuri recently discovered a stored XSS in all versions from 2.0 (released in November 2012) of the popular WordPress plugin Jetpack. The plugin has over 1 million active installs and is made by Automattic, the company behind WordPress. The vulnerability can easily be exploited via wp-comments and allows hackers to take over administrator accounts.
[Solution] Upgrade to Jetpack version 4.0.3
Read Jetpack’s comment on the vulnerability here.
As always, we recommend you to run regular security tests on your website to keep up with all the latest vulnerabilities.
Stay safe!

Tl;dr We’ve made a few improvements to Attack Surface Custom Policies, such as viewing alerts more easily and deleting custom policies. We’ve also made a …

Validate security policies like you mean it Not everything on your attack surface is a vulnerability. Every organization has their own internal security policies that …