Tom's Lemmy
  • Communities
  • Support Lemmy
  • Search
  • Login
Selfhosted@lemmy.worldbysanitation@lemmy.today
7 hours

PSA WordPress Core had Critical Vulnerability. Patch released on Friday. Immediately update

slcyber.io English

7.0.2 got released on Friday. Exploits are already happening. People reporting hacks

15
    wp2shell: Pre Authentication RCE in WordPress Core › Searchlight Cyber
    slcyber.io
    Critical issue discovered in WordPress Core affecting the majority of WordPress-built sites. The zero-day is a pre-authentication Remote Code Execution (RCE) that can be used by attackers to run malicious code to steal data or seize control without requiring login details...
    You must log in or register to comment.
    • xziiñiik@feddit.clEnglish
      2 hours

      thank god i was able to convince my boss to let go the old wordpress site and only serve static pages when he wanted to have a brand new design, its been about 2months with the new design

      • CausticFlames@sopuli.xyzEnglish
        8 hours

        Friendly reminder to anyone who cares enough that you can still use WordPress to make your site with all your fancy plugins and layouts, and then export that to a static site for hosting. No need to actually host Wordpress itself that way you avoid nearly all of this BS.

          • ElectricMachman@lemmy.sdf.orgEnglish
            3 hours

            Not a bad idea. How would one do this?

              • CausticFlames@sopuli.xyzEnglish
                56 minutes

                Simply Static is currently the most actively maintained solution, as a plugin for wp:
                https://docs.simplystatic.com/category/6-user-guides

                There is also WP2Static, which is a very long standing project: https://github.com/elementor/wp2static

            • ThanksObama@sh.itjust.worksEnglish
              11 hours

              Correction: WordPress IS a critical vulnerability.

                • 9point6@lemmy.worldEnglish
                  9 hours

                  https://www.wordfence.com/threat-intel/vulnerabilities

                  The CVE list always cracks me up, there’s like tens daily

                    • chronicledmonocle@lemmy.worldEnglish
                      46 minutes

                      JFC I thought you were exaggerating.

                    • SreudianFlip@sh.itjust.worksEnglish
                      7 hours

                      Anyone who hosts websites can check the logs and see the bots hammering away at wp/admin primarily, even if you are not running any WordPress. Low hanging meat? Fresh fruit?

                      • Marthirial@lemmy.worldEnglish
                        10 hours

                        I have developed and hosted over 760 WP sites since 2006 and have never been hacked. Ever.

                        Mediocre craftspeople blame their tools.

                          • ElectricMachman@lemmy.sdf.orgEnglish
                            3 hours

                            How do you know?

                            • genzboomer@lemmy.zipEnglish
                              5 hours

                              Professionals are never cocky. Cocky comes back to bite.

                              • kungen@feddit.nuEnglish
                                8 hours

                                I’ve driven a poorly designed car without many safety features for years, and I’ve never flown through the windshield, ever.

                                • loo@lemmy.worldEnglish
                                  10 hours

                                  Glad you got lucky. But a tool having one critical vulnerability after another has nothing to do with mediocre craftsmanship and blaming admins for getting hacked after updating their software is nothing but disrespectful and condescending

                              • lIlIlIlIlIlIl@lemmy.worldEnglish
                                10 hours

                                It’s time to ditch WP if you haven’t already

                                  • non_burglar@lemmy.worldEnglish
                                    10 hours

                                    It was time in 2013.

                                  Selfhosted@lemmy.world

                                  selfhosted@lemmy.world
                                  <p>A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t c

                                  Subscribe from Remote Instance

                                  Create a post
                                  You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

                                  A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

                                  Rules:

                                  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

                                  2. No spam posting.

                                  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

                                  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

                                  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

                                  6. No trolling.

                                  7. No low-effort posts. This is subjective and will largely be determined by the community member reports.

                                  Resources:

                                  • selfh.st Newsletter and index of selfhosted software and apps
                                  • awesome-selfhosted software
                                  • awesome-sysadmin resources
                                  • Self-Hosted Podcast from Jupiter Broadcasting

                                  Any issues on the community? Report it using the report flag.

                                  Questions? DM the mods!

                                  Visibility: Public

                                  This community is visible to everyone.

                                  • 841 users / Day
                                  • 2.09K users / Week
                                  • 6.54K users / Month
                                  • 11.4K users / 6 months
                                  • 1 local subscriber
                                  • 60.9K subscribers
                                  • 3.24K Posts
                                  • 55.6K Comments
                                  • Modlog
                                  • UI: 1.0.0-alpha.12
                                  • BE: 1.0.0-alpha.15
                                  • Modlog
                                  • Instances
                                  • Docs
                                  • Code
                                  • join-lemmy.org