WordPress Vulnerability Report: WPScan 4.0.0 Released
Introduction
The latest version of WPScan, 4.0.0, focuses on addressing community feedback and enhancing security scanning capabilities for WordPress sites.
Vulnerability Explanation
This update eliminates automatic scans of plugins, which previously consumed unnecessary API requests. Instead, WPScan now offers explicit control over what gets scanned, allowing users to customize their scans based on specific needs.
Affected Component
The changes primarily affect the scanning behavior of plugins and configuration backups.
Impact
By enabling more precise scanning, users can avoid wasting time and resources on irrelevant checks, thereby enhancing overall site security.
Fix
Users can manage scans by using specific commands to include or exclude plugins, ensuring only relevant components are analyzed.
Risk Level
With an emphasis on user control, the risk level is significantly reduced, making WPScan 4.0.0 a safer option for WordPress administrators.
Source: View Original Report
