{"id":27342,"date":"2019-06-17T23:54:45","date_gmt":"2019-06-17T23:54:45","guid":{"rendered":"http:\/\/4ea0558e-6dc8-489e-9bdc-674954099c69"},"modified":"2019-06-17T23:54:45","modified_gmt":"2019-06-17T23:54:45","slug":"disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/","title":{"rendered":"Disgruntled security firm discloses zero-days in Facebook&#8217;s WordPress plugins"},"content":{"rendered":"<p><span class=\"img aspect-set\"><img decoding=\"async\" src=\"https:\/\/zdnet1.cbsistatic.com\/hub\/i\/2018\/09\/12\/d4d4ce94-282b-47c8-bb39-e39b68d72333\/11f78e6dcfed50e15e5751e21b8e0984\/wordpress.jpg\" class alt=\"wordpress.jpg\"><\/span><\/p>\n<p>A US-based cyber-security firm has published details about two zero-days that impact two of Facebook&#8217;s official WordPress plugins.<\/p>\n<p>The details also include proof-of-concept (PoC) code that allows hackers to craft exploits and launch attacks against sites using the two plugins.<\/p>\n<h3>Impacted plugins<\/h3>\n<p>The two zero-days impact &#8220;<a href=\"https:\/\/wordpress.org\/plugins\/facebook-messenger-customer-chat\/\" target=\"_blank\" rel=\"noopener noreferrer\">Messenger Customer Chat<\/a>,&#8221; a WordPress plugin that shows a custom Messenger chat window on WordPress sites, and &#8220;<a href=\"https:\/\/wordpress.org\/plugins\/facebook-for-woocommerce\/\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook for WooCommerce<\/a>,&#8221; a WordPress plugin that allows WordPress site owners to upload their WooCommerce-based stores on their Facebook pages.<\/p>\n<p>The first plugin is installed by over 20,000 sites, while the second has a userbase of 200,000 &#8212; with its statistics exploding since mid-April when the WordPress team decided to start shipping the Facebook for WooCommerce plugin as part of the official WooCommerce online store plugin itself.<\/p>\n<p>Since then, the plugin has garnered a collective rating of 1.5 stars, with the vast majority of reviewers complaining about errors and a lack of updates.<\/p>\n<h3>The grudge<\/h3>\n<p>Nevertheless, despite the bad reputation, today, the security of all users who installed these extensions was put at risk because of a stupid grudge between a Denver-based company called White Fir Design LLC (dba Plugin Vulnerabilities), and the WordPress forum moderation team.<\/p>\n<p>In a dispute that&#8217;s been raging for years, the Plugin Vulnerabilities team decided they wouldn&#8217;t follow a policy change on the WordPress.org forums that banned users from disclosing security flaws through the forums, and instead required security researchers email the WordPress team, which would then contact plugin owners.<\/p>\n<section class=\"sharethrough-top\" data-component=\"medusaContentRecommendation\" data-medusa-content-recommendation-options=\"{&quot;promo&quot;:&quot;promo_ZD_recommendation_sharethrough_top_in_article_desktop&quot;,&quot;spot&quot;:&quot;dfp-in-article&quot;}\">\n<\/section>\n<p>For the past years, the Plugin Vulnerabilities team has been disclosing security flaws on the WordPress forums in spite of this rule &#8212; and having its forum accounts banned as a result of their rule-breaking behavior.<\/p>\n<p>Things escalated this past spring when the Plugin Vulnerabilities team decided to take their protest a step further.<\/p>\n<p>Instead of creating topics on the WordPress.org forums to warn users about security flaws, they also started publishing blog posts on their site with in-depth details and PoC code about the vulnerabilities they were finding.<\/p>\n<p>They disclosed security flaws this way for WordPress plugins such as Easy WP SMTP, Yuzo Related Posts, Social Warfare, Yellow Pencil Plugin, and WooCommerce Checkout Manager<\/p>\n<p>Hackers quickly caught on, and many of the details the Plugin Vulnerabilities published on their site were integrated into active malware campaigns, some of which <a href=\"https:\/\/www.zdnet.com\/article\/mailgun-hacked-part-of-massive-attack-on-wordpress-sites\/\" target=\"_blank\" rel=\"noopener noreferrer\">led to the compromise of some pretty big websites<\/a>, along the way.<\/p>\n<h3>Not that dangerous &#8212; but still zero-days<\/h3>\n<p>Today, the Plugin Vulnerabilities team has continued their spree of dropping zero-days instead of working with plugin authors to fix the vulnerabilities.<\/p>\n<p>They published details about two cross-site request forgery (CSRF) flaws that impact the two aforementioned Facebook WordPress plugins.<\/p>\n<p>The two flaws allow authenticated users to alter WordPress site options. The vulnerabilities aren&#8217;t as dangerous as the ones revealed earlier this year, as they require a little bit of social engineering where a registered user clicks on a malicious link, or an attacker manages to register an account on a website they want to attack. They might be harder to exploit, but they do allow attackers to take over sites.<\/p>\n<p>Nonetheless, just like before, the Plugin Vulnerabilities team completely ignored proper cyber-security etiquette and published details on their blog instead of contacting Facebook in private to have the bugs resolved.<\/p>\n<p>A message was posted on the WordPress.org forums but was deleted according to the site&#8217;s policy.<\/p>\n<p>In an explainer the company posted on its blog, Plugin Vulnerabilities tried to justify its course of action by claiming Facebook&#8217;s bug bounty program isn&#8217;t clear if the company&#8217;s WordPress plugins are eligible for rewards, and tried to pin the blame on the social network for limiting access to the program only for users with a Facebook account.<\/p>\n<p>Their excuses are flimsy, to say the least, as their record of past disclosures shows they aren&#8217;t really trying that hard to notify developers, and are merely making a spectacle on the WordPress forums about their ability to find vulnerabilities as part of some misguided marketing stunt for a commercial WordPress security plugin they are managing.<\/p>\n<p>For obvious reasons, the Plugin Vulnerabilities team <a href=\"https:\/\/medium.com\/@xorloop\/wordpress-security-researcher-gone-rogue-a76484ed0fc9\" target=\"_blank\" rel=\"noopener noreferrer\">is not very well liked in the WordPress community right now<\/a>.<\/p>\n<h3>More vulnerability reports:<\/h3>\n<p>READ MORE <a href=\"https:\/\/www.zdnet.com\/article\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/#ftag=RSSbaffb68\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Zero-days disclosed in &#8220;Facebook for WooCommerce&#8221; and &#8220;Messenger Customer Chat.&#8221;<br \/>\nREAD MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":27343,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[62],"tags":[],"class_list":["post-27342","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-zdnet-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Disgruntled security firm discloses zero-days in Facebook&#039;s WordPress plugins 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Disgruntled security firm discloses zero-days in Facebook&#039;s WordPress plugins 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-06-17T23:54:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"440\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Disgruntled security firm discloses zero-days in Facebook&#8217;s WordPress plugins\",\"datePublished\":\"2019-06-17T23:54:45+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\\\/\"},\"wordCount\":721,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins.jpg\",\"articleSection\":[\"ZDNet | Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\\\/\",\"name\":\"Disgruntled security firm discloses zero-days in Facebook's WordPress plugins 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins.jpg\",\"datePublished\":\"2019-06-17T23:54:45+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/06\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins.jpg\",\"width\":1000,\"height\":440},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Disgruntled security firm discloses zero-days in Facebook&#8217;s WordPress plugins\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Disgruntled security firm discloses zero-days in Facebook's WordPress plugins 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/","og_locale":"en_US","og_type":"article","og_title":"Disgruntled security firm discloses zero-days in Facebook's WordPress plugins 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-06-17T23:54:45+00:00","og_image":[{"width":1000,"height":440,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Disgruntled security firm discloses zero-days in Facebook&#8217;s WordPress plugins","datePublished":"2019-06-17T23:54:45+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/"},"wordCount":721,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins.jpg","articleSection":["ZDNet | Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/","url":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/","name":"Disgruntled security firm discloses zero-days in Facebook's WordPress plugins 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins.jpg","datePublished":"2019-06-17T23:54:45+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/06\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins.jpg","width":1000,"height":440},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/disgruntled-security-firm-discloses-zero-days-in-facebooks-wordpress-plugins\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Disgruntled security firm discloses zero-days in Facebook&#8217;s WordPress plugins"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/27342","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=27342"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/27342\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/27343"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=27342"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=27342"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=27342"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}