Hackers exploit WordPress plugin flaw that gives full control to 12M sites
arstechnica.com
arstechnica.com
- Decoupling through a process boundary interacting via RPC (This expands plugin backends to be able to be written in other languages or even compiled. Front-end plugin components could/would need to be rendered and composited separately in a way that cannot leak out.)
- Require administrative approval to grant particular permissions
- Cryptographic signatures of plugins by authors and web-of-trust maintained by Wordpress
- Capability-based API that can only be invoked after delegated permissions as above
PS: Project to remove XUL https://docs.google.com/document/d/1ORqed8SW_7fPnPdjfz42RoGf...