Thanks for allowing non-technies to set up their own site but no thanks--I'm good.
Thanks for allowing non-technies to set up their own site but no thanks--I'm good.
If there's a request for cgi-bin should we throw apache away, too?
I also find it interesting that you as a core dev narrow down possible answers by using "serious" and "lately" in your question. Of course you specifically ask for "WordPress exploits" as well, maybe because themes and plugins run with the same privileges as WordPress core code, and there's no review process for official plugins hosted on wordpress.org? Not to mention from other sources..
The aforementioned bug is in the phpass library used in WordPress. As fun as implementing our own cryptography is, we use the phpass library to abstract ourselves from this. Personally, I'd say this is something that phpass should be handling, as the use of crypt_private() is an implementation detail that we shouldn't need to know or worry about.
(This is also an issue that affects a small portion of sites, as "Exploitation of this vulnerability is possible only when there is at least one password protected post on the blog.")
As to the response from the security team (which is not exactly the core team), that's something I've called them out on before. Security is a serious issue that is usually handled very well on WP's behalf, but there have been a few notable instances lately where it's not.
(Also, the reason I "narrow down" the answers is because there are smaller "security" issues that tend to boil down to "admins can do anything", which is intentional.)
Wp is/was using the library wrong
Plugins run in the same process, with the same privileges, because there is basically no other way to do it.
OK, sure, you can do a kind of kabuki theatre where you present an API and insist plugin authors use it. But then they can access everything anyway and can find the MySQL login details by introspection. So it's pointless.
Another reason why I think apps should target virtual machines and be designed from the OS up. In such a design you can isolate plugins as standalone users and standalone processes.
Every time one of our WP developers asks me to help with something (usually they assume its a server config issue) I'm astounded at the shit I find when I discover the source of the problem.
Wordpress is not alone in this. It's the platform.
But no such system can prevent any plugins from doing whatever they want to do.
But yeah, if you have to host such software virtualization and isolation is a good idea.