Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That’s awesome, now can you find one that points to all the plugins that cause these security exploits? Because none of those are from the default WordPress install with the Standard plugins (ACF Pro, CPT UI, etc).


Here's one from this year: https://www.cvedetails.com/cve/CVE-2022-21664/

"SQL injection due to improper sanitization in WP_Meta_Query", fixed in WordPress itself:

https://bugzilla.redhat.com/show_bug.cgi?id=2039317

https://github.com/WordPress/wordpress-develop/commit/c09ccf...


Those are all related to Wordpress core.

Plugins are categorized separately from WordPress on the CVE website.


THIS. Impressive how experienced developers and professionals fall for this fallacy all the time because, wait, they don't actually KNOW A THING about wordpress.


It’s an interesting semantic game, but ultimately not very revealing. The platform is what gave you the vulnerability; whether it was core, a theme, or a plug-in is a matter of trivia. Especially considering the plug-in “store” is curated. Contrary to your assessment I’ve deployed quite a few things with Wordpress before.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: