7.0.2 got released on Friday. Exploits are already happening.
4 of my customers websites got hacked. I was busy the last days and weren’t up to date.
Good time to notice that 2 backups failed without me noticing it. Fml
Friendly reminder to anyone who cares enough that you can still use WordPress to make your site with all your fancy plugins and layouts, and then export that to a static site for hosting. No need to actually host Wordpress itself that way you avoid nearly all of this BS.
sanitation@lemmy.today
CausticFlames@sopuli.xyz
LunarLoony@lemmy.sdf.org
yuman@programming.dev
xzinik@feddit.cl
ThanksObama@sh.itjust.works 1 day ago
Correction: WordPress IS a critical vulnerability.
ctenidium@lemmy.world 3 hours ago
Elementor makes it worse though.
9point6@lemmy.world 1 day ago
www.wordfence.com/threat-intel/vulnerabilities
The CVE list always cracks me up, there’s like tens daily
chronicledmonocle@lemmy.world 19 hours ago
JFC I thought you were exaggerating.
SreudianFlip@sh.itjust.works 1 day ago
Anyone who hosts websites can check the logs and see the bots hammering away at wp/admin primarily, even if you are not running any WordPress. Low hanging meat? Fresh fruit?
Marthirial@lemmy.world 1 day ago
I have developed and hosted over 760 WP sites since 2006 and have never been hacked. Ever.
Mediocre craftspeople blame their tools.
kungen@feddit.nu 1 day ago
I’ve driven a poorly designed car without many safety features for years, and I’ve never flown through the windshield, ever.
How do you know?
genzboomer@lemmy.zip 1 day ago
Professionals are never cocky. Cocky comes back to bite.
loo@lemmy.world 1 day ago
Glad you got lucky. But a tool having one critical vulnerability after another has nothing to do with mediocre craftsmanship and blaming admins for getting hacked after updating their software is nothing but disrespectful and condescending