Skip to content

feat(cve5): support WordPress ecosystem extraction - #5832

Open
jess-lowe wants to merge 37 commits into
google:masterfrom
jess-lowe:feat/support-wordpress
Open

jess-lowe wants to merge 37 commits into
google:masterfrom
jess-lowe:feat/support-wordpress

Conversation

@jess-lowe

Copy link
Copy Markdown
Contributor

Adds support for extracting and converting WordPress vulnerability data (Core, Plugins, Themes) from CVE5 records, with tailored handling for Wordfence, Patchstack, and WPScan CNAs.

Changes

  • Added heuristics to extract plugin/theme slugs and determine specific WordPress sub-ecosystems from references and metadata.
  • Introduced WordpressExtractor with hookable handlers (WordfenceHandler, PatchstackHandler, WPScanHandler) to address CNA quirks (e.g., version normalization, automated reference generation).
  • Ensures both GIT (if available) and ECOSYSTEM ranges are produced for maximum fidelity, keeping them distinct to respect ecosystem boundaries.
  • Implemented robust fallbacks to generate ECOSYSTEM ranges from CPE or description text when standard Git resolution is unavailable.

Rationale
WordPress records often rely on SVN or custom CNA identifiers rather than standard Git commits. This change enables high-fidelity ingestion of WordPress-specific data while retaining linkage to Git history where possible, ensuring comprehensive coverage for WordPress users.

G-Rath
G-Rath previously approved these changes Aug 12, 2026

@G-Rath G-Rath left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ooohhh I just realized I'll need to figure out how WordPress versions work for semantic 🫠

…ted-level contract

Refactor VersionStrategy from a per-version interface with numeric priorities to a slice-ordered, Affected-level contract using ExtractionState to atomically track consumed version entries and prevent duplicate extractions. Also unify CPE fallback extraction across cpeApplicability and affected[].cpes, memoize per-repo version tag resolution in ProcessRanges, and fix Linux conversion outcome counting in AddAffected.
@jess-lowe
jess-lowe marked this pull request as ready for review October 1, 2026 01:30

@another-rex another-rex left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The PR description mentions extracting GIT, but I don't think the strategies actually extract git commits?

wpPluginTracRegex = regexp.MustCompile(`plugins\.trac\.wordpress\.org/browser/([^/]+)`)
wpPluginSvnRegex = regexp.MustCompile(`plugins\.svn\.wordpress\.org/([^/]+)`)
wpPluginOrgRegex = regexp.MustCompile(`wordpress\.org/plugins/([^/]+)`)
wpThemeTracRegex = regexp.MustCompile(`themes\.trac\.wordpress\.org/browser/([^/]+)`)

@another-rex another-rex Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you change [^/] to also include /?# characters? Incase the url doesn't end on a trailing slash.

@jess-lowe

Copy link
Copy Markdown
Contributor Author

The PR description mentions extracting GIT, but I don't think the strategies actually extract git commits?

it did once upon a time. (one of those 37 commits ago lol) I'll look into it

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants