• Home
  • Search
  • Understanding vulnerabilities in plugin-based web systems
  • Cite Icon13
  • https://doi.org/10.1145/3233027.3233042Copy DOI Icon

Understanding vulnerabilities in plugin-based web systems

  • Sep 10, 2018
  • Oslien Mesa +6 more
Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

A common software product line strategy involves plugin-based web systems that support simple and quick incorporation of custom behaviors. As a result, they have been widely adopted to create web-based applications. Indeed, the popularity of ecosystems that support plugin-based development (e.g., WordPress) is largely due to the number of customization options available as community-contributed plugins. However, plugin-related vulnerabilities tend to be recurrent, exploitable and hard to be detected and may lead to severe consequences for the customized product. Hence, there is a need to further understand such vulnerabilities to enable preventing relevant security threats. Therefore, we conducted an exploratory study to characterize vulnerabilities caused by plugins in web-based systems. To this end, we went over WordPress vulnerability bulletins cataloged by the National Vulnerability Database as well as associated patches maintained by the WordPress plugins repository. We identified the main types of vulnerabilities caused by plugins as well as their impact and the size of the patch to fix the vulnerability. Moreover, we identified the most common security-related topics discussed among WordPress developers. We observed that, while plugin-related vulnerabilities may have severe consequences and might remain unnoticed for years before being fixed, they can commonly be mitigated with small and localized changes to the source code. The characterization helps to provide an understanding on how typical plugin-based vulnerabilities manifest themselves in practice. Such information can be helpful to steer future research on plugin-based vulnerability detection and prevention.

Similar Papers
  • Book Chapter
  • Citations2

Is This IoT Device Likely to Be Secure? Risk Score Prediction for IoT Devices Using Gradient Boosting Machines

  • Jan 01, 2022
  • Lecture notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering
  • Carlos A Rivera A +3
  • Research Article
  • Citations22

Time series forecast modeling of vulnerabilities in the android operating system using ARIMA and deep learning methods

  • Jan 14, 2021
  • Sustainable Computing: Informatics and Systems
  • Kerem Gencer +1
  • Conference Article
  • Citations41

CVExplorer: Multidimensional Visualization for Common Vulnerabilities and Exposures

  • Dec 01, 2018
  • Vung Pham +1
  • Research Article
  • Citations20

Transferability of Machine Learning Algorithm for IoT Device Profiling and Identification

  • Jan 15, 2024
  • IEEE Internet of Things Journal
  • Priscilla Kyei Danso +6
  • Research Article
  • Citations11

Empirical Validation of Automated Vulnerability Curation and Characterization

  • May 01, 2023
  • IEEE Transactions on Software Engineering
  • Ahmet Okutan +6
  • Conference Article
  • Citations14

Predictive vulnerability scoring in the context of insufficient information availability

  • Oct 01, 2013
  • Hamza Ghani +4
  • Research Article

Enhancing Vulnerability Reports With Automated and Augmented Description Summarization

  • Dec 01, 2025
  • IEEE Transactions on Big Data
  • Hattan Althebeiti +5
  • Conference Article
  • Citations3

Implementation of Distributed Attack Penetration Testing Automation Using Dynamic Infrastructure Framework Axiom on Web-Based Systems

  • Nov 07, 2023
  • Pratama Aji Prisadi +3
  • Conference Article
  • Citations81

Finding A Needle in a Haystack: Automated Mining of Silent Vulnerability Fixes

  • Nov 01, 2021
  • Jiayuan Zhou +6
  • Research Article
  • Citations1

Threat intelligence named entity recognition techniques based on few-shot learning

  • Sep 01, 2024
  • Array
  • Haiyan Wang +4
  • Conference Article

A FMEA Analysis on Web Applications

  • May 30, 2023
  • Gabriel Petrică +1
  • Conference Article
  • Citations14

SQL Injection Vulnerability Identification from Text

  • Feb 25, 2021
  • Dhruv Parashar +2
  • Book Chapter

Chapter 9 - Security Metrics for Risk-aware Automated Policy Management

  • Nov 11, 2010
  • Autonomic Network Management Principles
  • E Al-Shaer +3
  • Book Chapter
  • Citations4

Towards a Vulnerability Tree Security Evaluation of OpenStack’s Logical Architecture

  • Jan 01, 2014
  • Doudou Fall +3
  • PDF
  • Research Article
  • Citations40

Predicting CVSS Metric via Description Interpretation

  • Jan 01, 2022
  • IEEE Access
  • Joana Cabral Costa +4
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.