The WPScan team interviews Vlad (also known as m0ze) who is a long-time contributor to the WPScan vulnerability database. Vlad shares thoughts on the state of WordPress security today:
“By itself, the WordPress engine is quite safe… but WordPress CMS is getting bigger and more complex… when you aim for perfection, you discover it’s a moving target.”
Vlad initially got started with ThemeForest after discovering vulnerabilities in a premium WordPress theme and several plugins: “The bottom line is that in about 15 minutes I found about 8 vulnerable themes on the marketplace…”