‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. zelphirkalt · · focus · HN ↗
    These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
    1. toyg · · focus · HN ↗
      TBF, some of it is structural: if you're the most popular anything on the internet, you'll be the most attacked and the most exploited, and hence the most exploitable.
      1. formerly_proven · · focus · HN ↗
        nginx serves a third of web traffic.
        1. tommica · · focus · HN ↗
          Nginx also has cves.
          1. coldtea · · focus · HN ↗
            Nowhere near what WP has, and nowhere near the crap design allowing it, and the clusterfuck of bad decisions WP has that enables them...
            1. Sohcahtoa82 · · focus · HN ↗
              WP is just RCE-as-a-Service.
          2. formerly_proven · · focus · HN ↗
            Yes, and most of them are low or medium impact and typically only apply to relatively niche modules or configurations. I can't recall any RCEs from this decade that were widely exploitable. The most recent one could be CVE-2026-42945 ("nginx rift"), but even that requires a really specific and kind of strange configuration.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.