‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. beezle · · focus · HN ↗
    "WordPress 7.1.2 has been released containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7"

    As a courtesy, I try not to say more than one bad thing about WP every day. FWIW about 1/3 of installs are not on the recent 7 branch.

    1. EGreg · · focus · HN ↗
      There was a time I looked up to Matt Mullenweg, but never to Wordpress.

      I&#x27;ve been building <a href="https:&#x2F;&#x2F;github.com&#x2F;Qbix" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;Qbix since 2008 and let me tell ya, I took a lot of great ideas from Drupal, Kohana, Symfony, etc. But never Wordpress. It&#x27;s just ... a mess. Wordpress just won by being first, basically. Kind of like Bitcoin.

      PS: Years ago, I hired a guy in Pakistan to work with me on some Wordpress sites, for clients. I thought that the Divi theme and basic Wordpress would be secure. Every one of those sites got pwned, badly. Sure, maybe it was the plugins. But why take the chance? In 2026 it&#x27;s way past time to not have to worry about basic security.

      1. krapp · · focus · HN ↗
        Wordpress wasn&#x27;t even first, Movable Type was the big thing before it.
        1. mgkimsal · · focus · HN ↗
          That was Perl though, wasn&#x27;t it? mod_perl more specifically, IIRC. That alone relegated to a small pool of users.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.