Critical issue discovered in WordPress Core affecting the majority of WordPress-built sites. The zero-day is a pre-authentication Remote Code Execution (RCE) that can be used by attackers to run malicious code to steal data or seize control without requiring login details...
7.0.2 got released on Friday. Exploits are already happening. People reporting hacks
Anyone who hosts websites can check the logs and see the bots hammering away at wp/admin primarily, even if you are not running any WordPress. Low hanging meat? Fresh fruit?
Glad you got lucky. But a tool having one critical vulnerability after another has nothing to do with mediocre craftsmanship and blaming admins for getting hacked after updating their software is nothing but disrespectful and condescending
Correction: WordPress IS a critical vulnerability.
https://www.wordfence.com/threat-intel/vulnerabilities
The CVE list always cracks me up, there’s like tens daily
JFC I thought you were exaggerating.
Anyone who hosts websites can check the logs and see the bots hammering away at wp/admin primarily, even if you are not running any WordPress. Low hanging meat? Fresh fruit?
I have developed and hosted over 760 WP sites since 2006 and have never been hacked. Ever.
Mediocre craftspeople blame their tools.
How do you know?
Professionals are never cocky. Cocky comes back to bite.
I’ve driven a poorly designed car without many safety features for years, and I’ve never flown through the windshield, ever.
Glad you got lucky. But a tool having one critical vulnerability after another has nothing to do with mediocre craftsmanship and blaming admins for getting hacked after updating their software is nothing but disrespectful and condescending