Comment by oliversild

1 day ago

I’m the CEO of Patchstack. We don’t accept vulnerabilities in our program that require admin privileges (even though there have been real cases where such vulnerabilities cause serious damage to multisite networks). The plugin vulnerability issues in WordPress have become significantly worse, as low severity issues are now chained together that become a severe issue. On top of that, these vulnerabilities are being exploited faster than ever before. WordPress now also has an issue with supply chain attacks - which has started to happen quite a lot more compared to past years.

“Their whole business model is to sign CVEs” - please don’t make up random stuff. We were invited to the CVE program and therefore have an obligation to assign CVEs.

“Get to rank them on Google” - what?

Also, we don’t send press releases about vulnerabilities. There are cases where publications reach out to us and ask for comments when there are severe issues disclosed - but that’s very much different from the picture you’re trying to paint here.

Also, your “get a half decent host with a WAF” argument shows how disconnected you’re from the reality. There are web hosts that say they offer secure hosting when promoting free SSL. We’ve tested the web hosts with independent reviewers and what you’re claiming is a widespread myth that has been debunked: https://patchstack.com/articles/myth-of-secure-hosting-only-...