WordPress plugin hole puts '2M websites' at risk
theregister.com
theregister.com
Emphasis mine.
It is not actually that hard to run Wordpress securely. Stick to supported plugins and themes, and install security patches quickly when they are released.
The vast, vast majority of WP attacks are based on known vulnerabilities, and only start after the details are disclosed. The bad guys who bother targeting WP are generally lazy and unsophisticated.
Obviously if you know you are a high value target, you may want to stand up additional defenses.
If a site is not mission critical or you don't have the time/budget to maintain it, just enable auto-update on everything. This will protect you from the vast majority of vulnerabilities. There is a very small chance an auto update may break something on the site.
If a site is mission critical, every 1-3 months you should take a backup, update manually, and do some testing to verify that nothing broke.
It's not rocket science and not particularly difficult or expensive.
There is a proposal to make auto-updating the default. But because WordPress has to support everything from millions of personal blogs to whitehouse.gov, a proposal like that is a complicated topic. Notably whitehouse.gov has never been hacked.
Pedantic, but you would have been vulnerable if someone else also found the hole, but kept it secret?
Sure, when an exploit makes into metasploit or gets published things are worse if you don't patch - but just because the barn door is closed now with a patch, it doesn't mean you were secure when there was a big hole in the door...
So making WordPress "secure" isn't "just install updates as they come out". That's just "don't be criminally negligent".
Every piece of software out there has exploitable bugs sitting in the code just waiting to be found. Software is, fundamentally and essentially, insecure in that it is built by humans who make mistakes. A static HTML site does not protect against this since it’s still being served by a flawed software stack. Nginx has undiscovered bugs; Linux has undiscovered bugs. For sure.
But from a practical perspective, anyone running a site just wants to keep the bad guys out today, by resisting the intrusion attempts they directly experience. And for the vast majority of Wordpress sites, that is achievable with correct file and directory permissions, strong passwords, and prompt patching.
Depending on your site's functionality, it may also be possible to run a static WP site:
* https://wordpress.org/plugins/simply-static/
You do all your regular updates via the CMS, but, instead of putting the dynamic site on the public Internet, you generate static files and point your public web server's HTML rootdir at those.
Wordpress is a highly target platform for hackers regardless of what plugins are used. ACF is a really good plugin in the WP ecosystem.
I vaguely remember another one that was nearly as ubiquitous and constantly causing people to get hacked - had a very generic name like "Contact Form 2000" or something.
"The vast majority of bloggers and small business owners that run WordPress sites … are not cybersecurity experts," Ellis said.
That audience is also unlikely to use ACF.
The majority of these folks pay someone to set up their website and then never touch it again until something breaks. This was the primary reasoning behind WordPress forcing automated updates.
The rest, I see it different. Most WP sites are self-setup (read: for "free") by the site owner. ACF has 2M installs. That's a fraction of total WP sites. Therefore, I conclude most WP site aren't setup by "designers".
Pretty much 100% of compromised WordPress sites I get are caused by a plugin like this, be it either a configuration issue or a vulnerability in code.
The ease and low cost of multi-tenant PHP environments combined with the incredibly massive resource base of themes and plugins basically makes it unstoppable for anyone needing something more than what Squarespace can offer in a budget web platform.
The fact that it can be shoe horned into doing so much at an "acceptable" level of quality makes it a nearly unkillable zombie.
Not quite. In the very distant past Movable Type was the incumbent and WordPress was the scrappy upstart trying to displace it.
Free PHP web hosting was easier to find.
I know there has to be a better way using modern tech.
I’m working on formulating your second requirement now. Some higher level features will certainly require a backend of some sort, but my original hypothesize was to eliminate a backend server and database if I can.
Some of my biggest challenges with Wordpress in the past were staying on top of updates and making sure my plugins didn’t get hacked.
I’m thinking I’m going to offer a simple and cheap hosted version soon that non tech people can login to and administrate all their content.
What a bummer... Strapi (and others) have a market share < 0.1 %
(I was using it for my blog and I found it relatively easy to set up)
Hell, Facebook doesn't even use PHP anymore having replaced it with a pseudo-superset, Hack.
If you want security, don't cargo-cult what everyone else is doing or use third-party code. Third-party code in dynamic languages is footgunning in a mine field.
Easy || popular != sustainable
It's an XSS vulnerability. There's 22,329 XSS CVE's across every language and platform you can imagine.
https://www.cvedetails.com/vulnerability-list/cweid-79/vulne...
It has nothing to do with "ancient". PHP is still a very strong language to be using even now - sure it isn't what the cool kids are using, but it is hardly ancient.
Third-party code is everywhere. What are you on about?
It has undergone many changes over the years, as evidenced by https://www.wpbeginner.com/news/the-history-of-wordpress/ and also taking advantage of PHP and MySQL improvements along the way.