‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. zelphirkalt · · focus · HN ↗
    These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
    1. toyg · · focus · HN ↗
      TBF, some of it is structural: if you're the most popular anything on the internet, you'll be the most attacked and the most exploited, and hence the most exploitable.
      1. atoav · · focus · HN ↗
        Yes and Wordpress is a pile of garbage.
        1. bartvk · · focus · HN ↗
          In what sense?
          1. sloat · · focus · HN ↗
            wp-includes/class-wpdb.php
          2. atoav · · focus · HN ↗
            In the sense that it and its ecosystem is high maintenance. When I call something names I do not do that lightly, but Wordpress is probably the single piece of software that has caused me the most problems over my 20 year IT career. You simply cannot put Wordpress into a customers hands, let it run for 5 years and expect it not to blow up in one way or another.

            Just today I spent three hours to manually fix a page where a customers site was defaced after they installed and then uninstalled a translation plugin. I had to write a script that manually check every single instance of translatable text there is on the website.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.