Having used the WordPress support forum for many, many years, I always looked to it as a place to discuss non-commercial plugin support. In addition to an occasional review for a plugin, that’s all I have ever used it for. I don’t ask for support for commercial plugins in the forum, and if a plugin author asks me to create a support ticket because the question *might* in any way relate to a commercial version, I create the ticket via the requested support channel.
I have ever only asked questions related to plugin vulnerabilities that already have a CVE (Common Vulnerabilities and Exposures) reported. Maintained by the MITRE Corporation since 1999 and sponsored by the U.S. Department of Homeland Security, the CVE system provides a common language for security researchers, vendors, and IT professionals to identify, track, and share information about specific software and hardware flaws.
If a CVE has been reported for a given plugin, I believe it is important for the plugin author, many of whom are volunteers and do not get directly paid for the plugins they create, be alerted. In some cases, the author is already aware of the CVE, although some are caught unaware. That is why I feel it should be reported via the WordPress forum for the respective plugin, if no one has already done so.
Imagine my surprise when two posts I posted recently were deleted. One I was notified about, even though the reason given was “Dont [sic] ask for exploits on WordPress forums”. There is a separate post detailing that fiasco.
The other post was silently deleted. By that I mean the post was being held for moderation (a lovely gift I now get after EVERY post since the ‘exploits’ post noted above). I always keep a separate tab open with new posts until I refresh and confirm the post was successfully posted.
In this case, when I refreshed the page where I created that post, the page couldn’t be found. I checked the plugin forum and, sure enough, my post was not there. I had reported the CVE for the plugin, Product Notices for WooCommerce, and also asked if anyone knew if the plugin was still being actively supported.
Since the CVE was going on 18 months old, I considered that a valid question. Maybe some moderator didn’t? I don’t know because of the silent treatment. Maybe WordPress doesn’t mind having vulnerable plugins in their repository. I would, but maybe they don’t care.
Perhaps they only care about this: “Extend your WordPress experience! Browse over 67,000 free plugins.” Rather than being honest and saying something like “Extend your WordPress experience! Browse over 67,000 free plugins. About 50,000 are solid; over 17,000 have vulnerabilities.” Truth in advertising isn’t always convenient, is it?
What can you do in the alternative? You can look for an alternative method to contact the plugin author. After a little bit of searching, I located an email address and sent an email that contained pretty much what I attempted to post in the WordPress forum. I have not received a reply, and there is no indication on their website that they have any connection to a WordPress plugin.
In the end, I used ChatGPT to patch the plugin Product Notices for WooCommerce. ChatGPT also identified a couple of shortcomings in the plugin design, so I implemented those changes as well. If you use this plugin, check out this post. It includes a link where you can download the patched version.

