WISP-1108: A WordPress Plugin Vulnerability Benchmark, with a 325-plugin untouched test set and a 100-CVE Wordfence external-validation set
收藏资源简介:
This record bundles three resources for evaluating WordPress plugin vulnerability detectors, all shipping the vulnerable and patched plugin source (ZIP) and diff-based, file-level ground truth (the PHP files each vendor patch changed). 1) WISP-1108, the development corpus. 1108 real, disclosed-and-patched vulnerabilities across 854 unique WordPress plugins, sourced from the Patchstack vulnerability database. Each record carries a 10-class vulnerability label (SQLi, XSS, broken access control, CSRF, PHP object injection, RCE, LFI, SSRF, arbitrary file upload, other), CVSS, affected/patched versions, disclosure date, and links to NVD and Patchstack. 2) The 325-plugin untouched test set. A slug-disjoint set from the same Patchstack source whose plugin slugs do not appear in the 1108 corpus, used to score a frozen engine on plugins it never saw. Includes the four-tool scan and a blinded 120-finding adjudication sheet. 3) The 100-CVE Wordfence external-validation set. An independent, non-Patchstack set of 100 WordPress plugin CVEs whose CNA is Wordfence (sourceIdentifier=security@wordfence.com, from the NVD 2.0 feed), one CVE per plugin, with every 1108-corpus slug excluded. Plugin source is the official wordpress.org repository (last vulnerable release versus first patched release). Note on plugin licensing: the bundled plugin archives are third-party WordPress plugins distributed under their own licenses (predominantly GPLv2+), redistributed unmodified for security-research reproducibility. The dataset metadata, labels, ground truth and documentation are released under CC BY 4.0.



