Plug 'n' Pray: Agentic LLM-based Detection of Potential Log File Exposures in Third-Party Content Management System Plugins
cs.CR
Submitted: 2026-09-15
Updated: 2026-09-15
Comments: To be presented and published at 19 th ACM Workshop on Artificial Intelligence and Security (AISEC'26) colocated with ACM CCS 2026
Code: https://github.com/kazet/wpgarlic
Project page: https://www.divaportal.org/smash/get/diva2:1852099/FULLTEXT01.pdf
License: http://creativecommons.org/licenses/by/4.0/
The gist: Content Management Systems (CMS), such as WordPress, power a large share of the web (58%), and their extensibility through third-party plugins is a major source of their popularity as well as of
Terminology
Abstract
Content Management Systems (CMS), such as WordPress, power a large share of the web (58%), and their extensibility through third-party plugins is a major source of their popularity as well as of their attack surface. One high-impact weakness that remains understudied is log file exposure by CMS plugins, which create log files for debugging or other purposes. If these files are insufficiently secured, they can disclose sensitive information (e.g. credentials, personal data) which has led to website compromises in the past. In this work, we present an agentic, LLM-based framework that automatically detects potential log file exposures in plugins of the most popular CMS (WordPress). Our agent analyzes each plugin by performing static and dynamic analysis. We evaluated our approach on the 300 most-installed WordPress plugins (about 0.6% of all), which together account for over 250M active installations, i.e. 75% of all active installations in the official plugin ecosystem. We manually validated each finding, reproducing 79 of 81 findings from 62 plugins. We observed that several protective measures appear to be implemented that we classify as creation-control (e.g. manual log activation) and access-control (e.g. deny rules in.htaccess). However, we find that multi-layered protection is required, but not always present. From these results we derive a taxonomy of log file path and protection patterns and deduce a set of best practices for developers to securely handle them. Finally, our study corroborates that agentic LLMs are an useful tool for security analysis.
Sources
- LLM Agents can Autonomously Exploit One-day Vulnerabilities
- RepoAudit: An Autonomous LLM-Agent for Repository-Level Code Auditing
- Execution-State-Aware LLM Reasoning for Automated Proof-of-Vulnerability Generation
- Over 100 Bugs in a Row: Security Analysis of the Top-Rated Joomla Extensions
- FaultLine: Automated Proof-of-Vulnerability Generation Using LLM Agents
- Top Score on the Wrong Exam: On Benchmarking in Machine Learning for Vulnerability Detection
- ReAct: Synergizing Reasoning and Acting in Language Models
- CVE-Bench: A Benchmark for AI Agents' Ability to Exploit Real-World Web Application Vulnerabilities
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs