‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. zelphirkalt · · focus · HN ↗
    These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
    1. traceroute66 · · focus · HN ↗
      > WP would surely be among the top candidates

      And its closely related cousin, Joomla.

      1. bombcar · · focus · HN ↗
        Joomla makes WP look like Fort Knox.
        1. foul · · focus · HN ↗
          It has its share of vulnerabilities but flaws in core are rarer, more (a lot more) (i swear to god a LLM would be better) in the modules ecosystem. Also like most CMSes they are still vulnerable to what i call the "webapp bug" (you install this blob on a hosting that should not be aware of what you dump on there and allows you to run a php file on any subdir, while with a CMS, whatever you use, only a very limited number of files should be allowed to be reached, executed or even included in any php call).
          1. bombcar · · focus · HN ↗
            All I remember with Joomla! is that it was really, really susceptible to the “plugin we use is abandoned and not updated and the new version of core is completely incompatible” causing everyone to run various out of date packages with stupid security layered on top. Web application firewalls are an abomination.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.