‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. beezle · · focus · HN ↗
    "WordPress 7.1.2 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7"

    As a courtesy, I try not to say more than one bad thing about WP every day. FWIW about 1/3 of installs are not on the recent 7 branch.

    1. EGreg · · focus · HN ↗
      There was a time I looked up to Matt Mullenweg, but never to Wordpress.

      I&#x27;ve been building <a href="https:&#x2F;&#x2F;github.com&#x2F;Qbix" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Qbix since 2008 and let me tell ya, I took a lot of great ideas from Drupal, Kohana, Symfony, etc. But never Wordpress. It&#x27;s just ... a mess. Wordpress just won by being first, basically. Kind of like Bitcoin.

      PS: Years ago, I hired a guy in Pakistan to work with me on some Wordpress sites, for clients. I thought that the Divi theme and basic Wordpress would be secure. Every one of those sites got pwned, badly. Sure, maybe it was the plugins. But why take the chance? In 2026 it&#x27;s way past time to not have to worry about basic security.

      1. krapp · · focus · HN ↗
        Wordpress wasn&#x27;t even first, Movable Type was the big thing before it.
        1. mgkimsal · · focus · HN ↗
          That was Perl though, wasn&#x27;t it? mod_perl more specifically, IIRC. That alone relegated to a small pool of users.
        2. segfaultbuserr · · focus · HN ↗
          WordPress began as a FOSS replacement of Movable Type after Moving Type 3 made the controversial decision to change its licensing fee for some features. So it was like a Unix&#x2F;Linux situation.
      2. pmlnr · · focus · HN ↗
        WP won by having a very simple but flexible admin page.

        Drupal admin was not for humans back then.

      3. tweetle_beetle · · focus · HN ↗
        A tale as old as time... I made money by outsourcing to third party labour to a much cheaper country than my own, using a third party low code theme builder and third party plugins I didn&#x27;t vet. All of my customers got hacked.

        This is the problem WordPress faces - it&#x27;s powerful enough for people to get stuff done on a shoestring. But the professionals who want to do things on a shoestring are also likely cutting corners elsewhere (hosting, backups, security, etc). In many cases there&#x27;s money changing hands and it&#x27;s easier to blame WordPress than poor decision making.

        I have more sympathy for those building with it on a shoestring for personal&#x2F;charitable projects who may lack the skills&#x2F;experience to follow <a href="https:&#x2F;&#x2F;developer.wordpress.org&#x2F;advanced-administration&#x2F;security&#x2F;hardening&#x2F;" rel="nofollow">https:&#x2F;&#x2F;developer.wordpress.org&#x2F;advanced-administration&#x2F;secu.... They&#x27;re probably better off on Wix or Squarespace.

    2. jeroenhd · · focus · HN ↗
      WordPress doesn&#x27;t to LTS. WordPress usually backports security fixes to older branches (like the 6.x branches) but going all the way back to 4.x isn&#x27;t something they&#x27;ll do for every fix. Who knows how many bugs lie in wait for older versions that are out of support.

      If you run WordPress, you should be aware of this already. Either upgrade to the latest versions, constantly and quickly, or have extremely restrictive WAFs up and ready. Especially if you have any plugins installed (as those are usually where the WordPress exploits are coming from).

      I&#x27;d recommend everyone unhappy only finding out about WordPress&#x27; long-standing support policy to ask their money back.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.