‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. zelphirkalt · · focus · HN ↗
    These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
    1. reaperducer · · focus · HN ↗
      If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates.

      People on HN love to talk smack about WordPress. After all these years, it's as much a reflex as shouting "walled garden!" every time there's an Apple story.

      Yet some of the biggest web sites on the internet run WordPress, and more importantly, some of the biggest hacking targets on the internet run WordPress.

      Prime example: whitehouse.gov.

      If you know what you're doing, WordPress fine. The same is true with every other piece of technology out there.

      But people on HN like to lump the good in with the bad because everything is binary.

      1. spogbiper · · focus · HN ↗
        > If you know what you're doing, WordPress fine.

        Probably true, but for whatever reason Wordpress seems to attract an awful lot of people that do not know what they are doing

        1. otherme123 · · focus · HN ↗
          Anecdote: we contracted a web page, and the guy started saying "it would be a Wordpress. It has very bad press, but it's because it is widely used". Ok, we start developing in the latest version of php, and soon he say "we have to go down a couple phpversions, because x pluging don't work in the latest". Requested version had a dozen critical CVEs. Plugin in question did something really basic, like a preview card with OpenGraph data, or something like that. Something a junior could code in a day.

          And that is insecure Wordpress: people lego-mounting sites without touching code, only with plugins.

          1. type0 · · focus · HN ↗
            > And that is insecure Wordpress: people lego-mounting sites without touching code, only with plugins.

            Works as intended, that's why WP has been so popular

            1. yangm97 · · focus · HN ↗
              Pros: it has a low entry barrier

              Cons: it has a low entry barrier

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.