I think reading this article, you are probably aware that Wordpress and its plugins is occupying a very large place in External attack surface landscape. While monitoring our client, we have under our monitoring more than 100 Wordpress, associates with more than 1,5k different plugins constantly removed and renewed, which raises again a new challenge in our automatization.
Detecting all plugins with their associated version was the first basic step we had quickly automated for our client. We want to be sure our solution will be able to detect all installed plugins, all versions, and of course all already known published vulnerabilities on the plugins.
But let’s face the reality of the figures. With more than 6 600 vulnerable plugins and more than 11k related CVE, you can quickly do the math: constantly warned our client about all CVE related to all their plugins will quickly become a mess, and, as always, impossible to patch especially when you have to manage 7k other assets exposed on internet.