‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. zelphirkalt · · focus · HN ↗
    These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
    1. toyg · · focus · HN ↗
      TBF, some of it is structural: if you're the most popular anything on the internet, you'll be the most attacked and the most exploited, and hence the most exploitable.
      1. Retr0id · · focus · HN ↗
        That's not really true.

        Edit: wow that's a lot of downvotes! I'm surprised people can't identify a trivial reasoning failure.

        1. dwattttt · · focus · HN ↗
          You could've included a little more nuance. An interpretation of your response is "being the most popular remotely accessible software" != "the most attacked", which would need defending.
          1. hdgvhicv · · focus · HN ↗
            25 years ago alache hosted about 10 times as many sites as IIS, yet IIS was always the one being backed.
          2. graemep · · focus · HN ↗
            I imagine anyone with any knowledge of the field could see the flaws in the claim that most popular = most attacked.

            Lots of counter examples and definitely no clear relationship. IMO its up to the person making the claim to provide evidence.

            1. dwattttt · · focus · HN ↗
              Just to expand on that nuance then, "attacked" is not restricted to "successful attacks".

              The most popular widely deployed software will be the most valuable to attack. That most fail is a function of other properties of the software.

      2. formerly_proven · · focus · HN ↗
        nginx serves a third of web traffic.
        1. tommica · · focus · HN ↗
          Nginx also has cves.
          1. coldtea · · focus · HN ↗
            Nowhere near what WP has, and nowhere near the crap design allowing it, and the clusterfuck of bad decisions WP has that enables them...
            1. Sohcahtoa82 · · focus · HN ↗
              WP is just RCE-as-a-Service.
          2. formerly_proven · · focus · HN ↗
            Yes, and most of them are low or medium impact and typically only apply to relatively niche modules or configurations. I can't recall any RCEs from this decade that were widely exploitable. The most recent one could be CVE-2026-42945 ("nginx rift"), but even that requires a really specific and kind of strange configuration.
      3. atoav · · focus · HN ↗
        Yes and Wordpress is a pile of garbage.
        1. bartvk · · focus · HN ↗
          In what sense?
          1. sloat · · focus · HN ↗
            wp-includes/class-wpdb.php
          2. atoav · · focus · HN ↗
            In the sense that it and its ecosystem is high maintenance. When I call something names I do not do that lightly, but Wordpress is probably the single piece of software that has caused me the most problems over my 20 year IT career. You simply cannot put Wordpress into a customers hands, let it run for 5 years and expect it not to blow up in one way or another.

            Just today I spent three hours to manually fix a page where a customers site was defaced after they installed and then uninstalled a translation plugin. I had to write a script that manually check every single instance of translatable text there is on the website.

      4. fragmede · · focus · HN ↗
        How many times has Google been hacked? It's not zero, but just because something is popular doesn't mean it has to get exploited. Repeatedly.
        1. snowwrestler · · focus · HN ↗
          There is only one Google and it is operated by professionals. Who do not need to disclose the vulnerabilities that they find.

          Wordpress is pretty much the exact opposite of that.

          1. ValentineC · · focus · HN ↗
            We can say the same about most of open source.

            It's the WordPress plugin ecosystem that's more often the security nightmare though.

            1. AdrenalinMd · · focus · HN ↗
              Yes, and if you take Linux for example, there are also tons of exploit for it.
              1. zelphirkalt · · focus · HN ↗
                True, but then again WP is a very simple system, in comparison to the Linux kernel, and WP operates on a very different level, at which it should be much easier to get right. Also WP is not written in C. Granted, PHP is not all that great either, but probably still miles ahead, when comparing it to having to write bug-free C code, as one doesn't have to deal with all the manual memory management stuff, which people, even experienced engineers _will_ get wrong at least sometimes (remember the Chromium statistics about vulnerabilities).
      5. acomjean · · focus · HN ↗
        And it's very extensible. With that power and flexibility come exploits
      6. teunispeters · · focus · HN ↗
        That's bad designs for you. Assume that just because it's widely visible, must mean it has exploits. (this is the only point on that list I'll call "that's bad logic" on).
        1. ASalazarMX · · focus · HN ↗
          Everything complex enough has exploits, you can't make exploits impossible with design, just less likely.
          1. teunispeters · · focus · HN ↗
            The point of engineering is measuring and confirming errors, and designing to mitigate them. Exploits are errors.

            Complexity does not lead directly to exploits, letting errors be ignored does. At what level an error can be ignored - that's quality control. And one can tell poor quality software by how exploitable it is.

            1. ASalazarMX · · focus · HN ↗
              > Complexity does not lead directly to exploits

              Indirectly then? More complexity means more interacting parts, more complex interaction might hide flaws in ways it's hard to predict without looking at the big picture, which might be too big for a single person to picture (he).

              I don't advocate for oversimplified systems, the same way I don't advocate for overcomplicated systems. I advocate for finding an equilibrium.

              1. teunispeters · · focus · HN ↗
                Well, one can design in ways to reduce attack surfaces. But then it also helps if your tools and infrastructure support that. PHP for instance, is famously unhelpful and often hostile to this, though.
      7. 0xbadcafebee · · focus · HN ↗
        Most attacked, sure. Most exploited? You get out of it what you put into it. If you work to make it more secure, it will stay more secure, popular or not.

        WordPress is a software design from the early 2000's - and not a particularly good example. Even back then there were more secure designs.

        Take QMail for example. A simple design, it had security baked in from the start, and remains one of the most secure software packages in history. This exploit would have been prevented if WordPress had followed QMail's security designs. Enforced data flow, avoidance of parsing, eliminating untrusted code, and eliminating bugs by choosing code paths with fewer variables, would've all prevented this bug.

        DJB wrote a paper on QMail[1] to try to explain what worked and what was unnecessary. Anyone implementing new software (and wants it to be secure) should consider these [and other] design points. Popular software doesn&#x27;t have to be bad software. [1] <a href="https:&#x2F;&#x2F;cr.yp.to&#x2F;qmail&#x2F;qmailsec-20071101.pdf" rel="nofollow">https:&#x2F;&#x2F;cr.yp.to&#x2F;qmail&#x2F;qmailsec-20071101.pdf

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.