top | item 31484146

(no title)

allenbina | 3 years ago

was it due to the core or a plugin?

discuss

order

waynesonfire|3 years ago

very vanilla wordpress, it was a basic blog site. I think the only plugins I used were google analytics and some basic theme. I would keep it updated whenever I remember but maybe it wasn't often enough. Not exactly sure what the vector was and from whatever quality of analysis I did, the system didn't appear damaged beyond the changes made to the wordpress folder and luckily, the damage didn't seem to escape the www-data user that the http server ran as.

dmje|3 years ago

I'm gunna suggest compromised hosting. The issues I've seen (once plugins / core / php is up to date and obvious stuff sorted) has been almost entirely on shared hosts.

dschiffner|3 years ago

his admin creds were probably

admin / abcd123!

waynesonfire|3 years ago

Guessing passwords? You don't even have to try that hard. Have you seen the list of WordPress CVEs?

Here is one just from January of this year,

https://www.debian.org/security/2022/dsa-5039

"Several vulnerabilities were discovered in Wordpress, a web blogging tool. They allowed remote attackers to perform SQL injection, run unchecked SQL queries, bypass hardening, or perform Cross-Site Scripting (XSS) attacks."