24

Guess what? 😱 WordPress has probably an SQL injection vulnerability. Check it out and fix your installations, when more info will be known:

https://twitter.com/ircmaxell/...

Comments
  • 29
    What? A vulnerability in WordPress? But their code is so clean and maintainable, their code base so robust...
  • 5
    probably? I don't use wordpress but from rants I conclude it is for sure has any vulnerability you can think of since usually users end up throwing million extension to their websites
  • 2
    How are you supposed to fix it when a) word press haven't fixed it and b) it hasn't been disclosed yet (afaik)

    I guess there is option c) uninstall?
  • 3
    @Jonnyforgotten I'd go with option C without looking back
  • 3
    Based on the tweet, it’s not exactly useful holding off with a full disclosure unless you’re a major plugin dev, whom can’t fix there plugins anyway.

    Good job 👍
  • 4
    It's 2017, how can there still be SQL injection vulnerabilities in such a famous framework ?
  • 0
    @Strannch it's still stupidly prevalent, owasp 2017 top 10 still has it near the top spot in their rc2 release
  • 0
    Again jezus
  • 0
    Wow Wordpress ha a vulnerability? Never heard that before...
  • 0
    That's like saying the sky is blue.
  • 3
    @Strannch Its 2017. They still use md5. That should explain enough 😷
  • 1
    @linuxxx instead they should use plain text. Nobody suspects that.
Add Comment