Return
PSSA: A Precise Static Analysis Framework for Detecting Vulnerabilities in CMS Plugins
DOI:10.1109/tdsc.2026.3712242.png)
Abstract
En 中文
Content management systems (CMS) have been the preferred option for rapidly developing web applications due to their convenience. Their extensive plugin ecosystems also allow for quick and easy expansion of web application functionality. With the increasing complexity of plugins, there has been a surge in plugin vulnerabilities, which pose a serious threat to the overall security of web applications. Current methods for analyzing plugins simply apply typical web application analysis techniques, which fail to consider the unique characteristics of plugins and lead to inaccuracy. This paper presents PSSA, a novel method for detecting web vulnerabilities in PHP-based CMS plugins. The proposed approach incorporates an in-depth analysis of the CMS framework’s context during plugin analysis and enhances the analysis of PHP object-oriented code to achieve precise vulnerability detection. To evaluate its effectiveness, we compare PSSA with existing tools for vulnerability detection using established vulnerability datasets. Our results demonstrate that PSSA outperforms other tools, detecting the highest number of vulnerabilities while minimizing false positives. Additionally, we apply PSSA in a comprehensive survey of popular WordPress plugins, evaluating 980 extensively used plugins. This thorough investigation brings to light 178 new vulnerabilities, 124 of which are found in plugins boasting over 1 million downloads. Our efforts also contribute to the acknowledgment of 82 CVE identifiers, further underscoring the impact and necessity of our research in enhancing CMS plugin security.
Keywords:
Vulnerability detection
static analysis
content management systems
Journal
IF:
7.5
Papers:
2.5K
Citations:
9.6K
Organization
Cited Papers
No cited papers available

