PPlamenu
HomeTrendingLive feedsPeopleGroupsRulesStaff
Sign in
PPlamenu
HomeTrendingLive feedsPeopleGroupsRulesStaff
Sign in

posted in Selfhosted

sanitation@sanitation@lemmy.today
edited⁨23⁩d

PSA WordPress Core had Critical Vulnerability. Patch released on Friday. Immediately update

7.0.2 got released on Friday. Exploits are already happening. People reporting hacks

slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core
Searchlight Cyberwp2shell: Pre Authentication RCE in WordPress Core › Searchlight CyberCritical issue discovered in WordPress Core affecting the majority of WordPress-built sites. The zero-day is a pre-authentication Remote Code Execution (RCE) that can be used by attackers to run malicious code to steal data or seize control without requiring login details...
410100
Open original page
BoostsQuotesFavs
ThanksObama@ThanksObama@sh.itjust.works
⁨23⁩d

Replying to @⁨sanitation@lemmy.today⁩

Correction: WordPress IS a critical vulnerability.

⁨Jul⁩ ⁨23⁩, ⁨2026⁩, ⁨11:46⁩en
4000
Open original page
BoostsQuotesFavs
Marthirial@Marthirial@lemmy.world
⁨23⁩d

Replying to @⁨ThanksObama@sh.itjust.works⁩

I have developed and hosted over 760 WP sites since 2006 and have never been hacked. Ever.

Mediocre craftspeople blame their tools.

4000
Open original page
BoostsQuotesFavs
loo@loo@lemmy.world
⁨23⁩d

Replying to @⁨Marthirial@lemmy.world⁩

Glad you got lucky. But a tool having one critical vulnerability after another has nothing to do with mediocre craftsmanship and blaming admins for getting hacked after updating their software is nothing but disrespectful and condescending

0000
Open original page
BoostsQuotesFavs
kungen@kungen@feddit.nu
⁨23⁩d

Replying to @⁨Marthirial@lemmy.world⁩

I’ve driven a poorly designed car without many safety features for years, and I’ve never flown through the windshield, ever.

0000
Open original page
BoostsQuotesFavs
genzboomer@genzboomer@lemmy.zip
⁨22⁩d

Replying to @⁨Marthirial@lemmy.world⁩

Professionals are never cocky. Cocky comes back to bite.

0000
Open original page
BoostsQuotesFavs
ElectricMachman@LunarLoony@lemmy.sdf.org
⁨22⁩d

Replying to @⁨Marthirial@lemmy.world⁩

How do you know?

0000
Open original page
BoostsQuotesFavs
9point6@9point6@lemmy.world
⁨23⁩d

Replying to @⁨ThanksObama@sh.itjust.works⁩

www.wordfence.com/threat-intel/vulnerabilities

The CVE list always cracks me up, there’s like tens daily

1000
Open original page
BoostsQuotesFavs
chronicledmonocle@chronicledmonocle@lemmy.world
⁨22⁩d

Replying to @⁨9point6@lemmy.world⁩

JFC I thought you were exaggerating.

0000
Open original page
BoostsQuotesFavs
SreudianFlip@SreudianFlip@sh.itjust.works
⁨22⁩d

Replying to @⁨ThanksObama@sh.itjust.works⁩

Anyone who hosts websites can check the logs and see the bots hammering away at wp/admin primarily, even if you are not running any WordPress. Low hanging meat? Fresh fruit?

0000
Open original page
BoostsQuotesFavs
ctenidium@ctenidium@lemmy.world
⁨22⁩d

Replying to @⁨ThanksObama@sh.itjust.works⁩

Elementor makes it worse though.

0000
Open original page
BoostsQuotesFavs