LATIDIA · Ciberseguridad
Plug 'n' Pray: Detección genética basada en LLM de posibles exposiciones de archivos de registro en complementos de sistemas de gestión de contenido de terceros
arXiv:2609.17164v1 Tipo de anuncio: nuevo Resumen: los sistemas de gestión de contenido (CMS), como WordPress, alimentan una gran parte de la web (~58%), y su extensibilidad a través de complementos de terceros es una fuente importante de su p
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.17164v1 Announce Type: new Abstract: Content Management Systems (CMS), such as WordPress, power a large share of the web (~58%), and their extensibility through third-party plugins is a major source of their popularity as well as of their attack surface. One high-impact weakness that remains understudied is log file exposure by CMS plugins, which create log files for debugging or other purposes. If these files are insufficiently secured, they can disclose sensitive information (e.g. credentials, personal data) which has led to website compromises in the past. In this work, we present an agentic, LLM-based framework that automatically detects potential log file exposures in plugins of the most popular CMS (WordPress).