Unpatched WordPress vulnerability allows code execution for authors
blog.ripstech.com
blog.ripstech.com
RIPS could have at least waited one more month. It sounds like Wordpress gave their HackerOne extension deadline.
Also, lots of typos and bad wording in the article makes it look even less professional. For instance, if I didn't know the context, the following sentence makes absolutely no sense:
"The value of $_POST[‘thumb’] could hold the, to the WordPress upload directory relative, path of any file, and when the attachement gets deleted, the file will get deleted with it as seen in the first listing."
It's a bit ridiculous that such a high-risk bug could be given so much time for it to be fixed, but that's how HackerOne's guidelines go. https://www.hackerone.com/disclosure-guidelines
(I'm personally a fan of a tiered system wherein high-risk bugs have a hard deadline of 3 months or less before public disclosure, and medium/low risk bugs a much longer deadline)
And people still justify using it 'because it's easy and simple for non-tech folks.' The non-profit world is _riddled_ with it.
And people still justify using it 'because it's easy and simple for non-tech folks.' The non-profit world is _riddled_ with it.
Another day, another OS vulnerability
And people still justify using it 'because it's easy and simple for non-tech folks.' The non-profit world is _riddled_ with it.
Another day, another Android vulnerability
And people still justify using it 'because it's easy and simple for non-tech folks.' The non-profit world is _riddled_ with it.
Another day another PDF/flash/etc exploit
And people still justify using it 'because it's easy and simple for non-tech folks.' The non-profit world is _riddled_ with it.
Another day another security breach of a major non-WP website
And people still justify using it 'because it's easy and simple for non-tech folks.' The non-profit world is _riddled_ with it.
It's one thing to have periodic vulnerabilities in fairly central technologies that have few alternatives, and whose developers take those vulnerabilities seriously.
It's another to consistently choose a technology that has visibly and consistently thrown security to the wind, leaves its users totally vulnerable, and has no reasonable fixes; especially when far, far more secure alternatives exist.
So no, I don't believe any of those are valid equivalencies. WordPress is not the 'right tool' for any job. And PHP itself is also culpable in similar fashion.
WordPress is simple to set up, simple to use, and has a huge community. In the real world, it is often the best choice.
I'm sympathetic to the idea that WP need not be exposed when a site can be delivered with static files. That's a fair argument that I agree with. But no one's advocating abandoning IOS or Windows or Android because if you install a certain app, or if you use a browser or open a certain type of file you run the risk of exploits. To advocate the throwing out the baby with the bathwater over a bug like this suggests you cherry pick your concerns and/or have an axe to grind.
> check_admin_referer('update-post_' . $post_id);
Seems like you wouldn't be able to actually use this vulnerability without a valid nonce, so I don't see how you would trigger this unless you have some sort of malicious plugin also installed on the site . . ?
An attacker could create such an account, then abuse a legitimate nonce to delete files.