WordPress 7.1.2: critical core security fix. Update now, then check inactive themes and comments.

Details

Vulnerabilities

Problems with the vulnerability scanner

Fix common vulnerability scanner issues when Security Ninja cannot create or update local vulnerability database files.

Cannot create folder or write vulnerability files

You may see PHP warnings in debug.log when Security Ninja cannot create directories or write files under uploads, for example:

Warning: mkdir(): No such file or directory in .../plugins/security-ninja/modules/vulnerabilities/...
Warning: file_put_contents(.../uploads/security-ninja/vulns/...): failed to open stream: No such file or directory

The vulnerability scanner needs to store compressed list files under:

/wp-content/uploads/security-ninja/vulns/

See Vulnerability database files.

Common causes

  • Custom permissions on /wp-content/uploads/ that block the web user from creating folders or files
  • Hardening rules (including .htaccess or host “protect uploads” features) that block writes or downloads into uploads
  • Disk full, or a host that quarantines new files under uploads

What to try

  1. Confirm /wp-content/uploads/ is writable by WordPress.
  2. Temporarily relax extra upload protection while you activate Security Ninja or force a vulnerability list refresh, then turn protection back on.
  3. Check that security-ninja/vulns/ exists after a refresh and that the .jsonl.gz files appear.
  4. If a host malware scanner deletes those files because they contain CVE descriptions, allowlist the security-ninja/vulns/ path. The lists are reference data, not an infection on your site.

Still stuck? Contact support with the exact warning lines from debug.log.

Still stuck? Get help or contact us.

Larger screenshot

Enlarged image