‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. zelphirkalt · · focus · HN ↗
    These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
    1. reaperducer · · focus · HN ↗
      If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates.

      People on HN love to talk smack about WordPress. After all these years, it's as much a reflex as shouting "walled garden!" every time there's an Apple story.

      Yet some of the biggest web sites on the internet run WordPress, and more importantly, some of the biggest hacking targets on the internet run WordPress.

      Prime example: whitehouse.gov.

      If you know what you're doing, WordPress fine. The same is true with every other piece of technology out there.

      But people on HN like to lump the good in with the bad because everything is binary.

      1. nkozyra · · focus · HN ↗

        [dead]

        1. ImPostingOnHN · · focus · HN ↗
          If the only gun you would choose to have is an unloaded one, you could just not have it, save a few hundred dollars, and lose no marginal utility.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.