‹ BackHN Continuity

Thread

WordPress: Unauthenticated path traversal leading to conditional RCE

240 points · 132 comments · vntok

  1. zelphirkalt · · focus · HN ↗
    These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
    1. reaperducer · · focus · HN ↗
      If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates.

      People on HN love to talk smack about WordPress. After all these years, it's as much a reflex as shouting "walled garden!" every time there's an Apple story.

      Yet some of the biggest web sites on the internet run WordPress, and more importantly, some of the biggest hacking targets on the internet run WordPress.

      Prime example: whitehouse.gov.

      If you know what you're doing, WordPress fine. The same is true with every other piece of technology out there.

      But people on HN like to lump the good in with the bad because everything is binary.

      1. nkozyra · · focus · HN ↗

        [dead]

        1. Zak · · focus · HN ↗
          Manual safety or not is a real debate among people who carry pistols for self defense and law enforcement, and no manual safety is the majority position. The reasoning is that an extra step when the user needs the pistol in an emergency is problematic, a properly designed pistol can only fire if the trigger is pulled, and a properly designed holster makes pulling the trigger impossible until the pistol is drawn. Nobody seriously advocates carrying an unloaded pistol for those purposes, and only lunatics advocate having people who don't know what they're doing carry pistols.

          It's not a great analogy to Wordpress, which attempts to provide as much capability as possible in a CMS while requiring as little expertise from the user as possible. Vanilla Wordpress, kept up to date is pretty safe. Plugins are just a click away though, and using plugins safely requires evaluating each plugin's risk profile and track record individually, which is real sysadmin work.

          1. nkozyra · · focus · HN ↗
            I think you've dissected this metaphor more than was necessary.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.