Your Theme, Plugin, Site Has a
Security Vulnerability
Now What?

WordCamp Toronto, 2015
Slides: https://adcwp.me/wcto2015

Aaron D. Campbell – https://aarondcampbell.com/
aaron@ithemes.com – @AaronCampbell
http://profiles.wordpress.org/aaroncampbell/
You’re
Vulnerable
What Now?

Your Users Are Your Priority
Security
Researchers
What you need from a reporter
- Steps to repeat
- Understanding on disclosure
Things a reporter might do
- Help fix the issue
- Test patches
What a reporter should NOT do
- Ask for money to give steps to repeat
- Ask for money to delay disclosure
What you need to do for a reporter
- Communicate
- Thank them:
- Props / Link to them
- Swag if you have it
- Payment if it makes sense
Time to Disclose Publicly?
No
plugins@wordpress.org
Fix It
Time to Disclose Publicly?
No
Get Trusted Users to Test
Prepare Release
Commit and update messages should mention that this is a security fix but not give details
Release Fix
Need a forced update?
security@wordpress.org
Time to Disclose Publicly?
No
A post about the new release and how important it is to upgrade could be helpful
How long do you wait?
My Rule of thumb: At least a day
Now you disclose publicly
What goes in a public disclosure?
- What could have happened
- What a user can look for to tell if they’ve been compromised
- Steps that can be taken clean things up
- No sugar coating
- No working examples
Remember
It doesn’t have to be scary
Your users are your priority
Q & A
Aaron D. Campbell – https://aarondcampbell.com/
aaron@ithemes.com – @AaronCampbell
http://profiles.wordpress.org/aaroncampbell/
Slides: https://adcwp.me/wcto2015
This presentation is running on WordPress using the Presenter plugin