[HN Gopher] WordPress themes, plugins backdoored in supply chain...
       ___________________________________________________________________
        
       WordPress themes, plugins backdoored in supply chain attack
        
       Author : prostoalex
       Score  : 445 points
       Date   : 2022-01-22 23:17 UTC (23 hours ago)
        
 (HTM) web link (www.bleepingcomputer.com)
 (TXT) w3m dump (www.bleepingcomputer.com)
        
       | turminal wrote:
       | For better of for worse, wordpress can at this point be
       | considered critical infrastructure.
        
         | rlt wrote:
         | It kind of boggles the mind, given vulnerability after
         | vulnerability throughout the 2000s and 2010s.
        
           | poink wrote:
           | Considering the other things we rely on, does it?
        
         | cblconfederate wrote:
         | why would it be for worse?
        
           | [deleted]
        
           | puskavi wrote:
           | Its too easy to setup and forget
        
           | howdydoo wrote:
           | Ideally our critical infrastructure would have a better
           | security track record
        
             | micromacrofoot wrote:
             | yeah and maybe companies will start paying for open source
             | software, but I'm not holding my breath
        
               | edgyquant wrote:
               | The difference is that it is bad for business reputation
               | when some of the largest companies on planet are
               | regularly leaking data through exploits. Testing will
               | become an economic requirement over time.
        
             | [deleted]
        
         | ARandomerDude wrote:
         | > For better of for worse
         | 
         | For worse.
         | 
         | > wordpress can at this point be considered critical
         | infrastructure.
         | 
         | True, sadly, though I'm thankful that after yet another
         | security incident the mid-size company I work for has decided
         | to officially end WordPress use across all our domains.
         | Hopefully, others will begin to do the same.
        
           | lordofgibbons wrote:
           | What is the company moving to for a replacement?
        
             | _HMCB_ wrote:
             | None better: https://processwire.com/
        
         | forinti wrote:
         | I don't like PHP or MySQL, but WP is a pretty decent piece of
         | software.
        
           | antihero wrote:
           | WP is possibly the most powerful and widely adopted footgun
           | we've ever seen.
        
           | smt88 wrote:
           | As someone who has been using WordPress since 2006, my brain
           | exploded when I saw this.
           | 
           | WordPress has always been an absolute mess. The basic
           | architecture was insane even in the early 2000s. There is no
           | effective sandbox for plugins or themes, and you can't really
           | make serious use of WordPress without those.
           | 
           | Nowadays, there are so many better applications that
           | accomplish the same thing, and they aren't stuck on a half-
           | baked database schema from 2003, they can be version-
           | controlled, multiple people can work on them at the same
           | time...
           | 
           | WordPress is one of the _worst_ widely used pieces of
           | software on the web. It is a catastrophe.
        
             | hanniabu wrote:
             | What are good alternatives these days that have as much
             | flexibility?
        
               | wilsonfiifi wrote:
               | Wagtail [0]
               | 
               | [0] https://wagtail.io/
        
               | post-it wrote:
               | Wagtail requires tens of hours of development to achieve
               | WordPress's stock functionality, and there are very few
               | plugins.
        
               | smt88 wrote:
               | The CMS space is incredibly crowded. The vast majority of
               | WordPress websites would be cheaper, faster, and more
               | secure if they were just moved to SquareSpace, which has
               | the WordPress features that 99% of sites would need.
               | 
               | For more custom projects, I prefer the headless
               | variety[1] because it makes sense to separate the data
               | and presentation layers. That means you have the full
               | ecosystem and flexibility of HTML/CSS/JS.
               | 
               | Ghost[2] was the first serious competitor I saw years
               | ago. Gatsby is among the most popular these days[3].
               | 
               | But honestly, information sites should just use
               | SquareSpace or something like it. There's no reason to
               | maintain static site infrastructure at this point.
               | 
               | 1. https://jamstack.org/
               | 
               | 2. https://ghost.org/
               | 
               | 3. https://www.gatsbyjs.com/
        
               | sascha_sl wrote:
               | If we're starting to compare to hosted offers, then
               | hosted WordPress (WP.org or any other managed host that
               | curates access to plugins/themes) surely needs to be
               | added back to the list?
        
               | invalidusernam3 wrote:
               | For enterprise level stuff, Drupal. Drupal development is
               | a pain in the ass, but it's incredibly powerful, has a
               | great community, and has a huge focus on security. But
               | for the average blog/site, Drupal is overkill and too
               | technical for what most people need
        
             | [deleted]
        
             | monkey_monkey wrote:
             | > here is no effective sandbox for plugins or themes, and
             | you can't really make serious use of WordPress without
             | those.
             | 
             | I mean, literally thousands of sites do make serious use of
             | WordPress. Quite surprised that in your use of WordPress
             | since 2006 you haven't heard about any of them.
        
               | pell wrote:
               | I think the commenter's point was that making "serious
               | use" of WordPress generally requires also using plugins
               | or theme(s).
        
           | lolinder wrote:
           | The trouble with WordPress is that it makes it _too easy_ to
           | set up and _far too easy_ to install random plugins.
           | 
           | People spin up a WordPress instance for their blog that
           | they're totally going to use every day, install a bunch of
           | plugins and a fancy theme, then within a few months have
           | completely forgotten about it. Meanwhile, vulnerabilities are
           | discovered in the plugins they installed. Maybe they're
           | patched and maybe they're not, but either way their server
           | doesn't get updated.
           | 
           | Within a few months it's hacked, and the ex-blogger probably
           | doesn't know until they get an email from their hosting
           | service complaining about malware being served from their
           | blog.
           | 
           | This is made worse by the fact that, since WordPress is
           | everywhere, it's worth the time for bad actors to write
           | scripts to exploit vulnerabilities in outdated versions of
           | popular plugins. It doesn't matter how obscure your site is,
           | if it's written in WordPress and not up-to-date, it's as good
           | as hacked.
        
             | Gigachad wrote:
             | The value of managed solutions for the every day
             | person/company is almost priceless. Squarespace / hosted
             | email / cloud storage etc should be standard vs
             | Wordpress/self hosted email/ a shared drive on the local
             | network.
             | 
             | Unless hosting the product is your core business model, let
             | someone else do it, because then there will be one or more
             | people dedicated to making sure it works perfect and is
             | regularly updated.
        
             | mattkevan wrote:
             | After building some sites with Wordpress recently, I think
             | another problem is the business model of most plug-in
             | vendors.
             | 
             | They all seem to charge $90 for a year of updates. Gets
             | steep quickly- theme, backups, layout builder etc. Fine for
             | the first year but probably don't get renewed and then the
             | plug-ins don't get updated.
             | 
             | I'd love to see a list of fully featured open source plug-
             | ins.
        
             | behringer wrote:
             | wordpress now allows auto updates,but this does require
             | setup and you still need to monitor for bad auto updates.
        
               | anakaine wrote:
               | Its also totally possible to be burned by auto updates.
               | Say for example if you're running php 7.3 and the vendor
               | specifies the plugin needs php 7.4 (even if it doesn't!)
               | . Your plugin gets updated, you get the white page of
               | death, your site is offline, and now you need to ftp/ssh
               | in and rename the directory for that plugin.
        
               | behringer wrote:
               | i'd rather have a white page of death than a security
               | issue. I have automated checks for the white page of
               | death too
        
         | marginalia_nu wrote:
         | In my search engine work, I found an enormous cluster of
         | websites that had a huge number of pages with link spam on
         | them, but with a seemingly legit front page. Sometimes
         | linkfarms will have some sort of a facade, but this was more
         | elaborate.
         | 
         | More confusing still, they were all on .net and .com-domains. I
         | just couldn't figure out what was going on, .com-domains are
         | expensive, typically link farms are on .xyz, .icu or something
         | similarly cheap.
         | 
         | I don't have the number, but I'm certain I identified tens of
         | thousands of them, if not a hundred thousand. That's close to a
         | million dollars in domain fees. The numbers didn't add up, who
         | would spend that sort of money on link farms? They were also
         | hosted all over, not just on Chinese clouds like most spam
         | offenders are.
         | 
         | It finally dawned upon me: What I was looking at was hacked
         | wordpress instances. Holy crap there's a lot of them floating
         | around.
        
           | hsbauauvhabzb wrote:
           | What is a link farm? How do they make money?
        
             | marginalia_nu wrote:
             | Wikipedia has an article:
             | https://en.wikipedia.org/wiki/Link_farm
             | 
             | But TL;DR: It's a form of search engine manipulation. The
             | theory is that if you put a bunch of links to your low-
             | ranking domain on a high ranking domain, search engines
             | will think your content is more valuable and be more likely
             | to crop up as top results. You set up a lot of these so
             | they promote each other, making it look like your shady
             | website is popular when it is not. It used to be more
             | effective than it is today, but it's still relatively
             | common.
             | 
             | Search engine manipulation doesn't need to be on these link
             | farms, it's also relatively common to for example have a
             | shady online casino raise their ranking by sponsoring open
             | source projects, which reward them by linking to the online
             | casino. That way the popularity of those projects will "rub
             | off" on the online casino.
        
           | christoph wrote:
           | A local 2nd hand Swiss watch dealer/shop runs their online
           | store off a Wordpress set up (no e-commerce/online payments
           | though). Sometimes when I visited to look at their current
           | stock, when clicking into something of interest I would get
           | bombarded with all sorts of random adware crap, new tabs etc.
           | opening with blogspam - typical "Win an iPad" type stuff.
           | 
           | The owner was totally unaware, as this never happens to them
           | - they are logged into the site the whole time, so it
           | deliberately never triggers/fires itself as they make
           | updates, etc.
           | 
           | It was also somewhat random for users of the site, but when
           | users see it, they probably just close it / ignore it.
           | 
           | Nobody told them this happened when browsing their website so
           | they were totally unaware they had been comprised.
           | 
           | Moral of the story, always occasionally browse your own web
           | properties from other devices and incognito windows, etc. to
           | see what other people see.
        
             | withinboredom wrote:
             | I've seen this on non-wp sites as well. So it's not just
             | specific to wp sites. Basically if you have a vulnerability
             | somewhere, someone is going to do this to your server.
        
           | throwawaynay wrote:
           | How did you find them exactly? I'm sure we can think of a way
           | to contact most of them automatically(or semi-automatically)
        
           | earthboundkid wrote:
           | If you follow WordPress sites on RSS, you see that they all
           | eventually get hacked if they go dormant. It's just a fact of
           | life.
        
           | tomrod wrote:
           | Consider publishing the list to ublock origin or something?
        
             | marginalia_nu wrote:
             | It's mostly a problem for search engines, they typically
             | don't want human visitors. Many of these wordpress installs
             | are innocent small businesses that just haven't realized
             | they're hacked.
        
         | sneak wrote:
         | Every WP site in the world could go down for a few hours and
         | nothing bad would happen.
         | 
         | That can't be said about critical infrastructure.
         | 
         | "critical" means something. If the water system or the power
         | grid goes down for a few hours, the world has a major problem.
         | 
         | If everything widely used is "critical infrastructure", then
         | nothing is.
        
           | thakoppno wrote:
           | humor me: what are the most critical pieces of internet
           | infrastructure?
           | 
           | i think i agree with you but then started to think that huge
           | whole parts of the Internet may not qualify by your
           | definition.
        
           | withinboredom wrote:
           | Heh, so much of the web runs WordPress. There are Facebook
           | domains running it, huge news sites, banks, budgeting
           | software, etc.
        
       | Wolfenstein98k wrote:
       | Everything you don't personally write is an attack vector.
        
       | Ericson2314 wrote:
       | We really need to purge ambient authority in this industry.
       | Completely.
       | 
       | The alternative is a low-trust low-collaboration regression to
       | 1990s style software development, and that is simply untenable.
        
       | enqc475u wrote:
        
       | dtjb wrote:
       | "BleepingComputer attempted to contact AccessPress about the
       | compromise, but the contact form is not working."
       | 
       | oof
        
         | freebreakfast wrote:
         | This isn't new, apparently. I found a tweet complaining about
         | the same from October 2021.[0]
         | 
         | 0. https://twitter.com/avillegasn/status/1450089053794230278
        
       | nicholast wrote:
       | The frequency of stuff like this is why I am still on Medium.
        
         | sascha_sl wrote:
         | If you "just" want a blog, simply ignore the plugins option (or
         | set WP_DISALLOW_FILE_MODS) and you get very similar outcomes.
        
       | MangoCoffee wrote:
       | every time a WordPress news show up on HN. there are a lot of
       | comments about WP being the worst software but where's the
       | replacement?
        
         | kop316 wrote:
         | Honestly, if you use wordpress for the basic functionality and
         | don't install plugins, it's pretty nice. You got a fully
         | functional blog, you can give non-technical users a login and
         | they know how to use it too.
         | 
         | You do have to be really careful about what plugins you
         | install, but there are useful ones out there.
        
         | thrwn_frthr_awy wrote:
         | Where's the replacement for what? Are you unaware of other
         | blogging platforms?
        
           | viraptor wrote:
           | WP is way past being a blogging platform. Try: replacement
           | for online multi-role portal editor with knowledgebase, shop,
           | forum, stock management, image gallery, document converter,
           | .... elements installable in 2 clicks.
        
             | amelius wrote:
             | So WP is really a web-based operating system.
             | 
             | There should be some competing products in this space.
        
             | thrwn_frthr_awy wrote:
             | Right, that's my point. It wasn't meant to be all that.
             | Maybe we aren't at the point where we can have all that
             | with two click installs.
        
         | xyzzy123 wrote:
         | I feel like WordPress sort of "wraps around" (quality horse-
         | shoe, it was so bad but popular that now it's good). Core
         | WordPress is one of the most audited codebases on the planet,
         | it has a ton of duct tape and scar tissue.
         | 
         | Any new relevant bug classes, people will tend to look for it
         | and fix it in WordPress first, because practically every bounty
         | program has one or more instances somewhere.
         | 
         | People aren't doing these kinds of attacks against WordPress
         | plugin distribution because it's uniquely vulnerable. They're
         | doing it because WordPress is incredibly popular.
         | 
         | If you need the stuff WordPress can do and can't get away with
         | a static site, IMHO it's usually still the best choice.
         | 
         | Main caveats being, plugin quality varies very widely
         | (including at supply chain level), and you can quickly run into
         | issues if you get an agency to customise and they do a bad job.
        
         | edgyquant wrote:
         | Wordpress is similar to forum software in that the modern
         | landscape have diversified and depending on what you are trying
         | to accomplish there are a ton of alternatives. Almost none of
         | them are a reimplementation of what Wordpress does though since
         | it comes from a time where you would purchase shared hosting
         | that came with Apache, PHP and MySQL built in. It's a giant
         | monolith that is as widespread as it is because 90% of everyone
         | who started a website in the 2000s used Wordpress.
        
         | selexin wrote:
         | I see Wordpress as a kitchen knife that is being sold to all
         | ages - I did have more to say in reply to your question, but
         | the more I think about it, the more I think that analogy speaks
         | for itself
        
         | nkozyra wrote:
         | From a technical sense there are plenty of alternatives, even
         | similarly disliked platforms like medium or wix.
         | 
         | The problem is none of them are interested in turning a basic
         | CMS into a wasteland of kitchen sink functionality that aims to
         | turn blogging software into the ultimate web swiss army knife.
         | 
         | People are happy to build blog software, but that's not what
         | WordPress' customer base wants. They want professional services
         | in the form of a grab bag of sketchy plugins. Nobody's going
         | down that path again.
         | 
         | If the goal were simply "let's build a better blogging
         | platform" or "let's build a better storefront platform" or
         | "let's build a better music venue website platform" there might
         | be a receptive audience. But the goal is "let's build all three
         | in one and also 500 other use cases." Who would see that as a
         | compelling goal in 2022.
        
           | ohashi wrote:
           | Storefront... you have Shopify. The most valuable use case,
           | people are building those. The problem is people want a
           | million different things for lots of other stuff. Shopify now
           | has its own ecosystem too. It's the nature of creating
           | popular platforms that businesses rely on.
        
           | propogandist wrote:
           | WIX is absolutely terrible, it cannot be compared to WP.
        
             | nkozyra wrote:
             | To be fair, I referred to it as "similarly disliked." From
             | a technical sense I'm less afraid of malicious plugins
             | destroying my business like I might be with WP.
             | 
             | My stance is if I'm doing X, my preference is to find
             | software or a platform that does X but not X, Y and Z.
        
               | propogandist wrote:
               | landing on a Wix page is noticeably worse for someone who
               | tries to limit ads and scripting. Everything has to
               | pretty much be off for a Wix page to work, it is very
               | heavy.
               | 
               | I can see how the lack of plugins may make it more secure
               | though. I haven't tried Wix, but squarespace is pretty
               | good for getting something out the door quickly. It's
               | quite limited otherwise and the customization of
               | wordpress makes it a very appealing CMS for most.
               | 
               | If WP provides security screens for add-ons and
               | integrates it into their hosting business it would
               | protect their ecosystem moat.
        
             | PinkPigeon wrote:
             | I concur, many of my clients are 'rescues' from Wix and
             | Wordpress and the only thing more hated than Wordpress is
             | Wix.
             | 
             | More often than not it comes down to the horrifyingly
             | confusing documentation, inconsistent UX, hilarious over-
             | promising the world + dog on landing pages, etc.
             | 
             | Also, exfiltrating a website from Wix (changing the
             | nameservers, which should take two seconds, like it does
             | with any other hoster) is a huge ordeal. They make it very
             | difficult.
        
         | sneak wrote:
         | Jekyll. Hugo. Netlify CMS. Disqus.
        
           | fullstop wrote:
           | Throw in Ghost as well
        
             | marc_io wrote:
             | And Publii for simple static blogs.
        
               | novok wrote:
               | Publii doesn't work well when you want to edit your one
               | blog from multiple computers. Hugo or whatever is not
               | much of a stretch and you can edit from your laptop and
               | desktop w/ git.
        
           | chipotle_coyote wrote:
           | None of those have a plugin ecosystem that remotely
           | approaches WordPress's, let alone the bevy of WP-specific
           | consultants. It is not much of an exaggeration to say that
           | companies can make WordPress do _anything_ without any real
           | programming on their part; this is just not true for the
           | developer-focused alternatives, no matter how much better
           | they are on a technical level.
        
         | jillesvangurp wrote:
         | Exactly, as much as I dislike dealing with it, it does allow
         | our sales and marketing people to do things like publish
         | content, fiddle with SEO, deploy custom redesigns of the
         | website, etc. Without much support from me. That's important
         | for me because I have more important things to do.
         | 
         | We've had multiple people do work on this setup. When we get
         | new people in, they already know how to work with it because it
         | is so widely used. We had a sales person with some Wordpress
         | experience setting up things like CMS integrations, do some
         | basic SEO, etc. Then recently we had a new designer that got
         | busy redesigning our website. All that stuff happened without
         | support from my side. That happened multiple times actually
         | since we have been working with student trainees a bit. It's
         | great. These people come in and they know how this stuff works
         | already and get things done without me having to spend a lot of
         | time on it.
         | 
         | That's it's main redeeming feature. It's horrible for technical
         | people to deal with but it's main feature is that non technical
         | people are able to use it without requiring assistance from
         | technical people. All I do is makes sure it stays up to date,
         | is configured properly, and make sure backups happen.
         | 
         | Other CMS solutions are available of course and I would
         | recommend anyone in a position to choose to use some hosted and
         | managed solution. Something like Squarespace or whatever rather
         | than setting up their own wordpress server. But there's nothing
         | that comes close in terms of non technical people actually
         | knowing how to work with it. It's been the go-to solution for
         | this stuff for a very long time now.
        
       | theden wrote:
       | I think it's clear that the fewer plugins one installs (ideally
       | none) the better, though it's difficult to follow this rule in
       | practice. I recently had to set up a WP website from scratch, and
       | plugins are a very common way for people to solve their problems
       | (especially non-technical users). Plugins are even used for basic
       | ops work like rewrite rules, backups, log parsing, caching--and I
       | get it, for most people if they didn't exist they wouldn't have
       | done the ops stuff, or solve many of the other types of problems,
       | so it's kind of a blessing and a curse given your attack surface
       | increases with each plugin and WP feature. I've learned that
       | Wordpress really is what you make of it, directly proportional to
       | the engineering effort you put in.
        
         | edgyquant wrote:
         | I don't think is really at all clear. Whether it's word press
         | plugins, or a few thousand JS or Python modules you install
         | with npm/pip, the market has moved into this direction because
         | it is the most efficient. The problem is 100% in testing which
         | is something most places slack of at because people joining, if
         | they do write tests at all, only test their additions to the
         | codebase.
         | 
         | It isn't just Wordpress, either, I think that testing of large
         | scale interconnected software is not yet a solved problem and
         | whomever can devise a system that eliminates all the
         | vulnerability types we've seen exploited over the last few
         | years will become very rich.
        
           | IncRnd wrote:
           | > I think that testing of large scale interconnected
           | software...
           | 
           | That's not the issue with WordPress plugins, which generally
           | suffer from unknown provenance and suspect security-posture.
        
           | harikb wrote:
           | Testing, while required, is an orthogonal problem. I haven't
           | seen a "test" in any ecosystem that can detect a malware
        
             | onion2k wrote:
             | You don't test for malware. You test to make sure the
             | attack vector that's used to install malware is closed to
             | attackers. For example, if you have an upload feature your
             | tests should check that your file type filtering actually
             | works, that things in your upload directory aren't
             | executable, that you can't upload to the path of an
             | existing file, and so on. You should build with security in
             | mind, and test that the code you wrote does what you think
             | it should do, and that it doesn't do things it shouldn't
             | do.
        
             | edgyquant wrote:
             | Yeah exactly, that's my point. We haven't been developing
             | and using a ton of test types we could realistically do now
             | given the proper incentives. At some point, with more and
             | more data being accumulated and more and more services
             | being brought online, we will have to start adding more
             | foolproof tests suites as it it's reaching a point where
             | it's not just company reputation but national security that
             | we're risking.
        
             | MeinBlutIstBlau wrote:
        
       | sascha_sl wrote:
       | If you professionally build a WordPress site, please consider
       | turning off the native plugin and theme management, and replace
       | it with composer and files non-writable to PHP.
       | 
       | https://roots.io/bedrock/ is a neat boilerplate for how this can
       | be done.
        
       | willis936 wrote:
       | A few hops to get to the list of known backdoored themes and
       | plugins:
       | 
       | https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-...
        
       | Helithumper wrote:
       | Timeline:
       | 
       | 2021-09-22: Jetpack Scan team discovers the dropper and back door
       | in the FotoGraphy theme, and tries to contact vendor about the
       | initial finding.
       | 
       | 2021-09-27: Confirm presence of dropper + back door in all
       | current free plugins and themes downloaded from vendors website.
       | 
       | 2021-09-28: Confirm that dropper + back door is not present on
       | downloads from wordpress.org
       | 
       | 2021-09-29: Trying to contact vendor again, with updates on new
       | findings.
       | 
       | 2021-10-14: Escalated to WordPress plugins team to try to obtain
       | contact with the vendor.
       | 
       | 2021-10-15: Compromised extensions are removed from the vendor's
       | site.
       | 
       | 2021-10-16: Response from vendor
       | 
       | 2022-01-17: Most plugins have been upgraded to new versions,
       | themes have been pulled from WordPress.org.
       | 
       | 2022-01-18 Public disclosure
        
         | hanniabu wrote:
         | So isn't the reasonable deduction here that the vendor was
         | responsible for this given it was present on their website but
         | not on the plugins through Wordpress? They probably didn't have
         | the back door on the wordpress plugins because those would face
         | a higher scrutiny than the ones on their site. Finally they get
         | caught and go silent, but then when wordpress knows they
         | finally respond because they know the jig is up and are trying
         | to save face.
        
           | ehnto wrote:
           | I think the more reasonable deduction is that the vendor's
           | website was compromised, and that's where the attacker was
           | able to introduce new files.
        
           | dannyw wrote:
           | I don't think that's a reasonable deduction, it seems like
           | the contact form on the vendor's website didn't work. That
           | could possibly be compromised by the attacker.
        
         | zzleeper wrote:
         | That's really pathetic, to put it mildly. Three weeks between
         | initial contact and removal of compromised themes. Four months
         | until public disclosure.
        
           | smoe wrote:
           | Public disclosure by the people that found the backdoor. I
           | couldn't find any disclosure about it by AccessPress
           | themselves between 15. October when they pulled the
           | compromised themes and plugins to now.
        
             | freebreakfast wrote:
             | ThriveThemes still hasn't released a disclosure on an
             | attack from March 2021.[0] This seems to be par for the
             | course among theme developers.
             | 
             | 0. https://www.wordfence.com/blog/2021/03/recently-patched-
             | vuln...
        
           | IncRnd wrote:
           | That's not the timeline. It was a single day from contact to
           | removal of compromised plugins. According to the article, the
           | issue was that the vendor's contact form didn't work, not
           | that the vendor didn't quickly remove the plugins.
           | 
           | You are also confusing plugins with themes. They are not
           | exactly the same.
        
             | jcun4128 wrote:
             | > vendor's contact form didn't work
             | 
             | Had this happen recently to a site. The SMTP password was
             | set wrong and I don't know how many months/years this form
             | just failed to submit but no one was aware of it... was for
             | a landing page type site.
        
           | john-doe wrote:
           | > The attack was discovered by researchers at Jetpack, the
           | creators of a security and optimization tool for WordPress
           | sites.
           | 
           | It's a deceitful way to present it. Jetpack and WordPress are
           | the same company.
        
             | monkey_monkey wrote:
             | It's not deceitful at all. Anyone who's in the WP ecosystem
             | understands this.
             | 
             | Jetpack is part of Automattic. Automattic's main thing is
             | wordpress.com (the hosted platform). Automattic and WP.org
             | are not the same thing even though ( as with many open
             | source projects that have commercial implications) the
             | lines are somewhat blurred.
             | 
             | Presenting this as "deceitful" is really quite the over-
             | reaction.
        
               | john-doe wrote:
               | If the lines are somewhat blurred, you can understand my
               | initial confusion, not being "in the WP ecosystem"
               | myself.
        
               | monkey_monkey wrote:
               | Sure. but perhaps think about the use of emotive words
               | like "deceitful" when you don't fully understand what's
               | going on?
        
               | john-doe wrote:
               | English as third language, so let's say I didn't realise
               | it was such a strong word.
        
               | Kye wrote:
               | English is a mess.
               | 
               | Deceitful implies intention. Qualifiers help.
               | "Unintentionally misleading" fits better. It's like the
               | difference between manslaughter (whoopsiedeath) and
               | murder (intentional).
        
               | kjs3 wrote:
               | You have to understand that this sort of intentional
               | obfuscation of ownership and responsibility under a
               | single root of ownership is in most areas of business a
               | pretty good indication of ill intent (even if it is
               | depressingly common).
        
             | withinboredom wrote:
             | That's simply not true. Jetpack is owned by Automattic.
             | Automattic has an exclusive license to the name "WordPress"
             | from the WordPress Foundation but WordPress is owned,
             | operated, and managed by the WordPress Foundation and is a
             | totally separate entity.
             | 
             | Source: I work at Automattic and used to work on a Jetpack
             | team.
        
               | freebreakfast wrote:
               | This is true, but it's also important to note that Matt
               | Mullenweg founded/co-founded and leads both
               | organizations.[0][1]
               | 
               | 0. https://www.linkedin.com/in/mattm/
               | 
               | 1. https://www.guidestar.org/profile/20-5498932
        
               | john-doe wrote:
               | Thanks for the clarification, it's not that easy to
               | understand when one looks at the Automattic website.
        
           | benatkin wrote:
           | I never download from anywhere but wordpress.org and a lot of
           | others don't, and that wasn't attacked, so I disagree that
           | it's "pathetic".
        
       | diontron wrote:
        
       | imglorp wrote:
       | As dismal as cesspools like Medium are, I'm starting to
       | understand why they're options to self hosting anything at all.
       | Managed services are someone else's security problem.
        
         | q1w2 wrote:
         | As someone who runs a small company that self hosts as well as
         | maintains our own hardware, it's great when things are running
         | smoothly (>95% of the time), but when there's a problem, it's a
         | complete time sink.
         | 
         | On one hand, it's much cheaper, it's fun, makes integration
         | work much easier, and I've learned a lot with each deep dive...
         | 
         | ...but on the other hand, it can be more stressful, causes more
         | downtime, and it a distraction to the mission of the company.
        
       | babbledabbler wrote:
       | I recently had to take over a wordpress site for a volunteer
       | project and it almost immediately got hacked with spam despite
       | taking great pains to not have this happen.
       | 
       | Thousands of SEO pages showed up in the DB after installing some
       | well known marketplace plugins. I was able to remove the hacked
       | plugin and fortunately, it wasn't a big deal as this was just a
       | temporary site for an event, but I would never work on wordpress
       | again and I dissuade people from using it when I hear that they
       | are considering it.
       | 
       | It was great for its day, but times have changed and it's just
       | not a secure platform.
       | 
       | Any benefit given by all the plugins is outweighed by "hack
       | roulette" you are playing when you install and customize them.
       | 
       | There are now many other solutions out there that will be more
       | secure and fit the need for most people.
        
         | chillfox wrote:
         | The key to running Wordpress securely is usually to set the
         | file permissions correctly and protect all admin routes.
         | Basically, don't expose any write endpoints to the internet.
         | 
         | And the easiest way is to use as few third party plugins/themes
         | as possible.
         | 
         | Base Wordpress is pretty secure if you put the admin panel
         | behind a VPN and don't install any plugins.
        
       | hirundo wrote:
       | "According to Sucuri researchers who investigated the case to
       | figure out the actors' goal, threat actors used the backdoor to
       | redirect visitors to malware-dropping and scam sites. Therefore,
       | the campaign wasn't very sophisticated."
       | 
       | "Threat actor" and "supply chain attack" sound like attempts to
       | elevate a crime into terrorism. As if their intent was to keep
       | food off of the shelves rather than theft and fraud. Aren't those
       | bad enough?
        
         | MathMonkeyMan wrote:
         | Policing language helps with marketing. I'm not saying I like
         | it, but what is the alternative? "Some randos with domain
         | knowledge and free time made the system do something other than
         | what its designers intended, and now are hoping that distracted
         | or gullible users will get fooled into scams"?
        
         | lolinder wrote:
         | Both of those terms are technical terms with specific meanings,
         | and they're used correctly here. It's no more intended to
         | scaremonger than when a medical journal uses fancy words for
         | different body parts... it's just how cybersecurity people
         | talk.
         | 
         | Threat actor: https://en.wikipedia.org/wiki/Threat_actor
         | 
         | Supply chain attack:
         | https://en.wikipedia.org/wiki/Supply_chain_attack
        
       | jeffbee wrote:
       | It's not a "supply chain attack" when you wantonly deploy
       | unreviewed code on your server. We don't need a fancy term for
       | it. It is just jackass behavior.
        
         | WaxedChewbacca wrote:
        
       | skilled wrote:
       | They are a pretty big vendor in the space, so it's quite
       | surprising not to see an official update from them on their blog.
        
       | etewiah wrote:
       | There has got to be a big market opportunity for people who
       | create "wordpress for xxxx" - alternatives for different sectors.
       | 
       | The sector where WordPress gets "mis-used" most is real estate.
       | It really isn't designed for that usecase:
       | https://smallbusinessforum.co/why-an-alternative-to-wordpres...
        
         | ohashi wrote:
         | Might be good to disclose you're promoting your own company
        
       | barneygale wrote:
       | Relevant bash.org: http://bash.org/?949214
       | 
       | > <azonenberg> wordpress is an unauthenticated remote shell that,
       | as a useful side feature, also contains a blog
       | 
       | Circa mid-00s
        
         | ozim wrote:
         | Having the knowledge of 2022 this can be said about any web
         | application or anything one exposes to the internet to be
         | accessed by randoms.
        
       | seanwilson wrote:
       | For people recommending static sites to replace WordPress, what
       | do you do if you want to give users a basic page builder in the
       | CMS where you can easily preview the page before it goes live?
       | 
       | E.g. bolting together page blocks for testimonials, feature lists
       | and a contact form with some basic customisation like colours and
       | images.
       | 
       | Markdown only support is straightforward but most company
       | websites need a bit more than this. Accurate page previews before
       | production deploys is really important too. Open source preferred
       | as well.
        
         | herbst wrote:
         | Even Wix has a more user friendly UI builder than wordpress
         | does. Every CMS I tried in the past years did.
        
         | hellojere wrote:
         | Next.js, and most likely all the big players, can achieve that.
         | I use Prismic for a lot of projects, and here's documentation
         | about how to achieve previews with it and Next.js
         | https://prismic.io/docs/technologies/previews-nextjs
        
           | post-it wrote:
           | Yeah, easy, all you have to do is rewrite WordPress in
           | JavaScript. Now instead of worrying about malware in plugins,
           | you can worry about malware in plugins _and_ your npm
           | dependencies!
        
             | fastball wrote:
             | The problem with WP is that its being run in a privileged
             | position. A statically generated site is not.
        
               | sdze wrote:
               | you don't run your fpm processes as superuser. In general
               | it is run in a jailed environment.
        
               | post-it wrote:
               | You shouldn't run your web server as root. I think the
               | most common way of running WordPress is to use nginx in
               | front of Apache, so you can easily run Apache as a
               | special WordPress user for extra security.
        
             | ekianjo wrote:
             | sounds like much worse than wordpress from the get go
        
           | seanwilson wrote:
           | Is there an open source CMS for this though? Prismic doesn't
           | seem to be: https://prismic.io/faq/product
        
           | [deleted]
        
         | PinkPigeon wrote:
         | My solution to this is https://pinkpigeon.co.uk
         | 
         | I built it specifically to address shortfalls of other site
         | builders:
         | 
         | - No themes
         | 
         | - Uses 'modules' rather than the strangely popular drag and
         | drop thing with blocks and widgets (which then jumble about the
         | page wildly when resizing). We have 40 modules at the moment
         | and I keep building more.
         | 
         | - 100% mobile optimised. We hide no functionality and most page
         | editing I tend to do side by side, with the CMS in a separate
         | window next to the preview site
         | 
         | - The preview site updates automatically when you hit 'save' so
         | that it can be viewed on many devices in real-time at the same
         | time (and shared easily too)
         | 
         | - It's very fast. No React or other shenanigans. There is JS
         | for the more complex interactions, but it's been applied
         | sparingly. Doesn't work without JS though.
         | 
         | - Sites are deployed to Cloudflare Workers Sites. The SSG
         | behind the scenes is Hugo
         | 
         | I don't advertise this thing anywhere and all my clients are
         | word of mouth. I have yet to hear a single negative thing from
         | anyone.
         | 
         | I live in the countryside so my clients are all pensioners who
         | don't know computers. They've all had run-ins with WordPress
         | and naturally hated it. (though I don't want to knock a
         | properly setup WordPress, IMO you have to be technical to do it
         | and my system is aimed specifically at non technical people)
         | 
         | I don't do shops and even blogs are probably not directly my
         | target audience. But if you just need to make a simple site
         | with pictures, videos and images (maybe a mailchimp signup,
         | instagram gallery or Google calendar signup or showing some PDF
         | newsletters), then I'd challenge you to do it faster in any
         | other system.
         | 
         | I'm doing this on the side, so have no time to build websites,
         | so it takes no time to build websites in my system :) (I've
         | built a lot of websites for free and just end up collecting the
         | hosting charge which is between PS8-PS13 a month, which is
         | hopefully similar to some sitebuilders, but I can't compete
         | with the PS3 per month offerings that tie you into other
         | services and immediately become more expensive as soon as you
         | add any meaningful functionality.)
         | 
         | There are about a billion things I want to improve about it of
         | course. It's certainly not perfect, but finding the time is a
         | challenge. I hope to one day be able to make it my full time
         | job.
        
         | chillfox wrote:
         | Give them a Wordpress site (on a VPN) that generates a static
         | site.
        
         | mateomorris wrote:
         | https://primo.af is exactly this. It's still in Alpha but I'm
         | releasing the Beta within the next few weeks.
        
           | SturgeonsLaw wrote:
           | There's a lot of domain hacks you can do with .af however I
           | imagine the sovereign risk of using a domain controlled by
           | the Taliban would be higher than average
        
           | Tepix wrote:
           | The animated headline causes the entire page to jump around
           | on iPhone 13
        
             | matesz wrote:
             | It probably happens on all mobile devices, I'm using iPhone
             | 12 mini. Very annoying!
        
               | [deleted]
        
             | mateomorris wrote:
             | Hadn't realized this - thanks for the heads up
        
         | berkes wrote:
         | The same as with any software: a deployment pipeline.
         | 
         | Depending on your needs, a staging version can be built and
         | hosted. To be promoted to production once chief editor Acks. Or
         | multiple such versions.
         | 
         | You can have multiple stages. Or just one, with a preview on
         | localhost. You can have testsuites crawling a build. Or just a
         | manual quick glance.
         | 
         | This problem is not hard. It is, in fact, much simpler to solve
         | with static sites.
        
           | seanwilson wrote:
           | Like say you want to update the heading text and background
           | image for a landing page header and check it looks good on
           | desktop and mobile. Does it line wrap nicely? Maybe bolding
           | some words would look good? Is the text still readable when
           | it overlaps the image? I want to be able to preview and tweak
           | this kind of thing in seconds.
           | 
           | What would you use for this? I wouldn't want to wait a minute
           | for Netlify to build and deploy to staging each time for
           | example.
        
         | vanchor3 wrote:
         | If you're not completely against markdown, I particularly like
         | Grav (https://getgrav.org) combined with the optional Admin
         | plugin. Very quick and easy installation; I don't need to keep
         | detailed notes on getting the exact packages loaded to make it
         | work. The admin plugin gets you easy editing capabilities,
         | although you still write in markdown by default it has quick
         | buttons for common markdown and a preview button.
        
         | Morgawr wrote:
         | > Accurate page previews before production deploys is really
         | important too. Open source preferred as well.
         | 
         | I just like to keep it simple and write markdown on a local git
         | repository that is mirrored on github + github pages for
         | viewing (but I'm sure there's other ways to do the same too).
         | You can just commit your changes locally to test that
         | everything works, and then push it to remote and it will get
         | picked up by "production". It works as a single user but I can
         | imagine working for a small team of contributors as well.
        
         | Casteil wrote:
         | Ghost - it can be self-hosted, and they provide an official
         | Docker image on Docker Hub
         | 
         | https://ghost.org/
        
           | nieve wrote:
           | Ghost is pretty decent, but it ties you to the node/npm
           | upgrade treadmill and has a few weirdnesses like pushing very
           | hard to get people to sign up for Mailgun instead of using
           | their own mail server.
        
       | 6510 wrote:
       | My blog is one small php file that can 1) load a html document
       | (that is a blog post) into a textarea. 2) Write out a html
       | document by sticking html above and below that what sits in the
       | text area. 3) find links to the html document on the index page,
       | rss feed and tag pages. 4) load and update the index and tag
       | pages. It does 4 whenever a html document (post) is saved.
       | 
       | There are no bugs in my code. There isn't enough of it to have
       | bugs.
       | 
       | php stopped working at least twice over the life of my blog. As
       | all pages are static html everything simply continued to work
       | with the exception that editing and posting had to be done over
       | ftp.
       | 
       | I download wordpress OS one time and spend a few hours gazing
       | over the thousands of files. I remember thinking sarcastically
       | how I wish I had that level of confidence in my own code. What
       | could possibly go wrong?
       | 
       | I do still admire the company and the project.
        
         | Dunedan wrote:
         | > I download wordpress OS one time and spend a few hours gazing
         | over the thousands of files. I remember thinking sarcastically
         | how I wish I had that level of confidence in my own code.
         | 
         | > There are no bugs in my code. There isn't enough of it to
         | have bugs.
         | 
         | Apparently you have a lot of confidence in your code.
         | 
         | I'm pretty confident if you'd post a link to your code here, it
         | wouldn't take long for people point out some bugs in it.
        
         | kichimi wrote:
         | >There are no bugs in my code. There isn't enough of it to have
         | bugs.
         | 
         | So I take it your code could handle a 1GB blog post safely
         | without giving you an error about exceeding post_max_size or
         | something similar?
         | 
         | That would be a bug.
         | 
         | Small code != bug free code.
        
       | throwthere wrote:
       | I'm not in this space anymore but 15 years ago backdoored wp
       | themes was par for the course.
       | 
       | Interesting to see how things have changed.
        
         | tannhaeuser wrote:
         | Plugin and theme vendors DDOSing each other via their WP plugin
         | code (that is, via your WP site), where one vendor is
         | supposedly selling other vendor's plugin/theme, is a thing [1]
         | (2019), so idk where you get the notion that things have
         | changed ;)
         | 
         | The whole "plugin" idea, where customization code can basically
         | modify and monkey-patch whatever functionality it desires, has
         | to go away, in WP and elsewhere. SGML has a concept of
         | declarative pipelined markup stream processors to decorate and
         | augment base HTML in a structured and bounded way. A "theme"
         | should ideally only consist of CSS not arbitrary PHP. But I
         | guess WP is a lost case, and has been for 20 years, in this
         | regard.
         | 
         | [1]: https://www.jemjabella.co.uk/2019/security-alert-pipdig-
         | inse...
        
         | jacquesm wrote:
         | More interesting to see how they didn't!
        
       | afrcnc wrote:
       | source, instead of this blog spam:
       | https://jetpack.com/2022/01/18/backdoor-found-in-themes-and-...
        
       | Tomte wrote:
       | Since most people don't seem to be aware: you can use Wordpress
       | as a mostly-static website generator.
       | 
       | Use WP Super Cache, and most of your pages are static anyway. A
       | small PHP stub will be hit still, but if you don't even want
       | that, you can just serve the generated static pages without it.
       | 
       | It's well documented, you just edit your httpd.conf/.htaccess or
       | your nginx config to serve the static files generated by the
       | plugins.
       | 
       | Only logged-in users (in most personal Wordpress installations:
       | "just me") or recent commenters, depending on configuration, hit
       | any PHP code at all.
       | 
       | Oh, and commenting works, unless with SSGs out of the box.
       | 
       | Keep the number of plugins small, use a static plugin and
       | security is mostly a non-issue for a personal weblog (it's
       | different for a "real" media operation with all kinds of
       | complicated workflows, of course).
        
         | Apofis wrote:
         | Wordpress is one of the most insecure platforms out there.
         | Avoid using it if you care about security.
        
           | herbst wrote:
           | All my logs, if wordpress or not, get constantly hammered
           | with random wordpress backdoor requests. Even if it were
           | generally secure, the one day it's not can break everything.
        
           | xorcist wrote:
           | PHP has a pretty good deployment story in FPM since 10+
           | years. Every worker can run in a read-only chroot, or with
           | separate uids.
           | 
           | Wordpress has only one entrypoint and only needs to write to
           | its data directory, so it's quite decent.
           | 
           | The big issue with wordpress is with the vast plugin system,
           | where all bets may be off depending on what you run.
        
           | Tomte wrote:
           | As I said: with this setup, all the readers (everyone but me)
           | do not even hit any Wordpress code anymore. It truly is a
           | static site generator. You can look at the generated HTML
           | files in the file system. That's what the web server serves.
        
             | speedgoose wrote:
             | If you can login or comment, you do hit Wordpress code
             | right?
             | 
             | It could be fine if you put the admin portal behind a
             | firewall but I would also recommend moving forward and stop
             | developing new websites using Wordpress if you care about
             | security. And you should probably care about security.
        
             | KarlKemp wrote:
             | If it generates something, it can still do whatever it
             | wants with the generated files if the purpose is to, for
             | example, embed spam links.
             | 
             | If the server is the target, it either still has access to
             | it, or to some alternative computer which, for a private
             | individual writing a blog, will be their much more valuable
             | personal device.
             | 
             | Yes, you can spin up a VM, generate html, run it through
             | all sorts of tests and only then upload it. The victims of
             | this hack aren't going to do that.
        
               | Tomte wrote:
               | That's a threat model that is wildly imaginative.
               | 
               | Tell your web server to only serve the login stuff to you
               | (certificates, HTTP Basic Auth, whatever). Problem
               | solved.
               | 
               | And what is your solution?
               | 
               | A SSG also generates something and could embed bad stuff.
               | 
               | Something has to upload your SSG generated files and thus
               | needs access to your web server. If you're running it on
               | your personal device it could compromise it.
               | 
               | Really, stop trying so hard to invent Wordpress problems.
               | If you don't like it, nobody forces you to use it.
        
             | ifdefdebug wrote:
             | Did you remove all the code pages? Otherwise, an attacker
             | is not restricted to following links on your site, they can
             | access the code urls directly?
        
               | Tomte wrote:
               | No, they can't. As I said, the nginx or Apache
               | configuration makes sure.
               | 
               | Look it up, you're routing everything to static files in
               | file system directories.
               | 
               | Only if you are requesting an URL (however "you" are
               | identified) the webserver even contemplates serving
               | something else.
               | 
               | It's an explicit rule for the special case. Everyone else
               | doesn't see a PHP-FPM execution path at all.
        
           | cyptus wrote:
           | just don't install tons of untrusted plugins and themes like
           | you would also not do on any other platform you host.
           | 
           | even whitehouse.gov uses WordPress:
           | https://wordpress.org/showcase/the-white-house/
        
           | goatherders wrote:
           | Simply not true. WP core is very secure.
        
           | apatters wrote:
           | This comment is a lame hit job. WordPress is the most widely
           | used publishing platform in the world and highly extensible,
           | so there are always going to be third party plugins and
           | themes which get compromised.
           | 
           | If security is a concern you can simply avoid third party
           | plugins and themes, or limit your use of them to reputable
           | vendors who have good track records.
           | 
           | The code of WordPress itself is pretty robust and the Core
           | team has a great history of fixing vulnerabilities quickly.
        
           | javchz wrote:
           | In my experience it's quite the opposite. It's not perfect,
           | but it's safe enough for most users.
           | 
           | As long as you have WP updated, and a good configuration with
           | your stack (PHP, MySQL, Nginx) it's hard to hack.
           | 
           | The main vulnerabilities come from 3rd party plugins and
           | themes, and shared hosting with older versions of the stack.
           | It's like faulting windows for vulnerabilities in an external
           | .exe app.
           | 
           | If you use the default setup, and follow security guidelines,
           | you should be ok.
        
             | jbverschoor wrote:
             | It _is_ windows ' fault. Its their platform, architecture,
             | their default configurations, sandbox, UX for security, etc
        
               | withinboredom wrote:
               | By this extension, you should be saying it is the Linux
               | kernel's fault all these sites were hacked.
        
           | KarlKemp wrote:
           | The issue here was plugins from compromised third-party
           | repository. This has little to do with WordPress. It's the
           | mechanism Apple refers to as justification for the App Store
           | monopoly which, I guesss, is hated on alternative days to
           | supply chain hacks.
        
           | anakaine wrote:
           | This comment is a load of nonsense. Wordpress core has
           | regular and comprehensive security reviews. Wordpress is the
           | most deployed publishing platform globally. Like with any web
           | application you should be deploying it behind a Web
           | application firewall with a fit for purpose ruleset, and
           | additionally with wordpress you can integrate one of several
           | application firewalls into the application - several of which
           | have decent full time security and development teams that
           | actively discover, patch and mitigate zero days and new
           | exploits.
           | 
           | Anything you add beyond that is on you, and you should be
           | vetting your vendors or own code properly.
           | 
           | I have to wonder what your purpose for attack here is. Are
           | you developing a competing product?
        
             | kevincox wrote:
             | I don't know enough to comment about WordPress. But a
             | secure applications don't need a WAF to be secure. WAFs in
             | the steady-state are really just fuzzy bug injectors that
             | hope to inject bugs over top of exploitable code.
             | 
             | The main use for WAFs that I consider valid is emergency
             | response to recently discovered vulnerabilities while a
             | patch is being discovered and applied.
             | 
             | The other use case is external rate limiting and DoS
             | protection. But most often it is better to do that in the
             | app anyways.
        
               | anakaine wrote:
               | They do plenty more than that:
               | 
               | - Can section off certain requests
               | 
               | - Can rate limit
               | 
               | - Can catch basic injection attacks
               | 
               | With the wafs that integrate with WP such as wordfence
               | they can also do things like:
               | 
               | - Check for bad file permissions
               | 
               | - Check for bad web server configuration
               | 
               | - Recieve ruleset updates for zero days that are actually
               | threat surface specific
               | 
               | Having a WAF in place that is threat surface specific
               | isn't as much about saying "its not needed if the code is
               | good" as much as it is saying "the code might not always
               | be good. We are not perfect. I'm at least going to have
               | an extra layer or two of defence to try and stay safe(r)
               | and give me some breathing room between an exploit and a
               | patch".
        
             | kichimi wrote:
             | It's just the oft touted "WordPress is insecure" meme.
        
           | simion314 wrote:
           | Your Favorite platform will be exactly the same if a bad guy
           | has access and inserts it;s code or if you are dumb enough to
           | install a random third party code from a random website.
           | 
           | My personal blog uses one of the default themes, I hosted
           | extremely cheap, I NEVER touch it because it is autoupdated
           | and it just works.
           | 
           | I did not review WordPress code so I can't tell how secure it
           | is, but using this article to do a lazzy hit on WordPress is
           | pathetic, this issue is as related with WordPress as you
           | installing an .exe fom a random website is a Windows issue.
        
             | sshine wrote:
             | WordPress is insecure by design.
             | 
             | tl;dr: Use a static site generator.
             | 
             | The biggest reason is that its pages are not statically
             | generated and allows for code execution when they contain
             | no dynamic content.
             | 
             | The second biggest reason is the marketplace for plugins
             | and themes; even if WordPress security audited their entire
             | standard release, every single theme or plugin you install
             | could compromise your installation. You'd think of a theme
             | as something that provides colors and spacing, but they're
             | fully executable programs.
             | 
             | WordPress is conveniently written in PHP, which attracts
             | inexperienced programmers with no understanding of web
             | security.
             | 
             | The attack that OP links to is a supply-chain attack made
             | possible by WordPress'es software architecture, but it
             | could have happened on most more secure alternatives if
             | they were equally popular.
             | 
             | So while it's easy to ridicule WordPress for having no
             | security and a poor architecture to withstand most attacks,
             | we mustn't forget that it's a combination of its huge
             | popularity and the ease of use caused by its simplistic
             | choices that has lead to this breach.
        
               | simion314 wrote:
               | >tl;dr: Use a static site generator.
               | 
               | Most People that use WordPress are not develoeprs or
               | technical people. Find similar product with a WYSIWYG GUI
               | , theme , plugins, cheap hosting, no bullshit licensing
               | or breaking backwards compatibility and promote it to
               | people or whoever hosts this blogs.
               | 
               | I think you are suggesting someone to replace his IDE
               | with notepad since you can build application with notepad
               | and gcc directly.
        
               | blowski wrote:
               | If the critics spent as much time building and selling
               | what they see as the "better option" to WordPress,
               | perhaps we wouldn't be in this place. As it is, they just
               | do the easy thing, playing "pigeon chess" by making these
               | hackneyed, unsupported assertions.
               | 
               | A better assessment is that WordPress has made trade-offs
               | regarding security, as anybody in the real world must.
               | Individuals must also make their own trade-offs,
               | including whether to run WordPress at all, then how to
               | configure it and which third-party code to use. Sometimes
               | we get the trade-offs wrong, and that should affect how
               | people make future decisions.
        
               | sdze wrote:
               | > WordPress is insecure by design.
               | 
               | Is there a proof for that?
        
           | ChrisMarshallNY wrote:
           | I have had a different experience. I've been using WP since
           | it was a wee bairn, and have written a number of plugins and
           | themes, over the years.
           | 
           | It is not for every use case. I think some of the new static
           | site generators are great, but WP fits the bill, when we need
           | a fairly dynamic, configurable, maintainable, site.
           | 
           | The "security issues" are, IMNSHO, a reflection of the much
           | wider "depenecapocalypse," that is plaguing the entire
           | software development industry, where lightly-trained, and
           | inexperienced, devs, slap all kinds of executables into their
           | projects, with hardly a glance at the _bona fides_ of said
           | executables, which, in my experience, can be ...
           | _questionable_.
           | 
           | I admit that I have created "Frankensites," by using too many
           | plugins (in fact, today, I am about to rewrite one, using as
           | "bare bones" an architecture, as possible). Even good plugins
           | can have a limited shelf life, and I have learned (the hard
           | way) that paying for extensions and themes buys me almost
           | nothing. I have been aghast, when examining the code, in some
           | of these.
           | 
           | There's a _lot_ of crap WP code, out there, but I have been
           | fairly impressed with the quality of the code and
           | architecture of the core system.
           | 
           | The one thing that I think needs improvement, is the
           | WordPress Codex. It's a mess. I'm often better served,
           | examining the code directly, than relying on that.
           | 
           | I don't do Web sites as a living. There's millions of better
           | Web developers than me. I like to be able to walk away from a
           | site, and let it stand on its own. WP has served me well, for
           | that.
        
             | marc_io wrote:
             | > The one thing that I think needs improvement, is the
             | WordPress Codex.
             | 
             | The original Codex can be considered obsolete as it has
             | been replaced by developers.wordpress.org which is much
             | more informative and up to date.
        
             | sdze wrote:
             | I personally love the WordPress Hook system. You really can
             | manipulate everything with plugins.
        
         | tenelmike wrote:
         | interesting info!
        
         | johnchristopher wrote:
         | But this doesn't protect from faulty REST entrypoints, XML-rpc,
         | wp-admin/* links, right ?
        
         | seanwilson wrote:
         | > Since most people don't seem to be aware: you can use
         | Wordpress as a mostly-static website generator.
         | 
         | > Use WP Super Cache, and most of your pages are static anyway.
         | 
         | This isn't "static" in the sense of a static site generator
         | because your web server is still running code, reading/writing
         | files, sending SQL queries, interpreting URL query parameters
         | (e.g. for search results pages) and injecting data into
         | templates when pages are being viewed. There is a much greater
         | attack area and types of possible attacks.
         | 
         | For example, the caching plugin itself you mentioned has had
         | remote code execution and XSS security holes in the last 6
         | months and others in the past:
         | 
         | https://patchstack.com/database/vulnerability/wp-super-cache
         | 
         | Many of these kinds of attacks aren't possible when your hosted
         | website is only HTML, CSS, JavaScript with a CDN in front.
         | Saying you think securing WordPress is practical is one thing,
         | but there's a huge difference between dynamic and static.
        
           | Tomte wrote:
           | > Many of these kinds of attacks aren't possible when your
           | hosted website is only HTML, CSS, JavaScript
           | 
           | Had you read the other comments, where I have replied to this
           | misconception several times already, you would have seen that
           | the setup I describe is just that: "your hosted website is
           | only HTML, CSS, JavaScript".
        
             | seanwilson wrote:
             | I'm replying to "Use WP Super Cache, and most of your pages
             | are static anyway", which means PHP is running each
             | request?
        
               | Tomte wrote:
               | You need to read past the second sentence where I explain
               | that WP Super Cache can be configured for fully static
               | operation.
               | 
               | Or if three sentences are too much for you, you could
               | read any of the other comments, all made hours before you
               | jumped in with your inane "well-actually".
        
               | [deleted]
        
               | seanwilson wrote:
               | Can you link to anywhere that explains more? Pages are
               | only generated when editors make edits and never from
               | requests from visitors? How do you regenerate when you
               | update the theme and what about tag, category and search
               | pages?
        
         | seumars wrote:
         | Or just use one of the hundreds of newer, more secure, CMS
         | alternatives out there.
        
           | nerdawson wrote:
           | Have those newer platforms been audited to the same extent as
           | WordPress? Even if the core of any new CMS is "more secure",
           | it'll be faced with the exact same problems the moment it
           | grows big enough that third-party developers begin to release
           | add-ons.
        
             | berkes wrote:
             | There is no need for e.g. Hugo, Jekyll, ghost or many such
             | setups to be audited. Because their model is inherently
             | secure.
        
         | pibechorro wrote:
         | This is true. But none of my clients have ever stuck to it. The
         | temptation is too great, within 6 months they always seem to
         | justify installing 20 plugins grinding their performance and
         | security to the ground.
         | 
         | I used to recommend WordPress, but I can't anymore, the plugin
         | system (and bloated themes) is a mess.
        
           | dgb23 wrote:
           | That seems like a people problem and not a tech problem. You
           | can simply not allow clients to install plugins and strip
           | other such capabilities.
        
             | yodon wrote:
             | It sounds like you've yet to experience having clients. The
             | decision-making authority generally flows quite differently
             | from what you imagine here. The nature of the decision-
             | making authority is what leads the parent commenter to
             | conclude they can't set clients up with WordPress in the
             | first place (because if they tried to tell the clients "no
             | you can't do that" the client would do so anyway and/or
             | switch to a new vendor do be able to do so).
        
               | lolinder wrote:
               | Yep. This was my experience with WordPress as an
               | employee. The marketing team was very loud about needing
               | admin access to the WordPress instance, installed a file
               | manager plugin, and that file manager plugin was shortly
               | used to start serving malware from our domain.
               | 
               | Guess who got to clean it up? It wasn't the marketing
               | team.
               | 
               | Yes, it's a people problem, not a technical problem. But
               | I arrived at the same solution to the people problem as
               | OP: don't set up a WordPress instance for someone who
               | isn't capable of maintaining security themselves.
        
         | Dunedan wrote:
         | At least when using nginx you don't even need WP Super Cache or
         | any other Wordpress plugin. Instead you can utilize Nginx'
         | FastCGI cache feature [1] which works for anything using
         | FastCGI and not just Wordpress.
         | 
         | Here is an example for a tutorial on how to configure the
         | FastCGI cache for Wordpress: https://easyengine.io/wordpress-
         | nginx/tutorials/single-site/...
         | 
         | [1]:
         | https://nginx.org/en/docs/http/ngx_http_fastcgi_module.html#...
        
           | lolinder wrote:
           | Caching solves only the performance problem, which in my mind
           | is the least compelling reason to go for static site.
           | 
           | If your wp-admin routes are still accessible to the public
           | internet, then you are still at risk for broken plugins
           | causing a hack. You have to both cache all static directories
           | _and_ firewall the actual server if you want to avoid being
           | hacked by one of the thousands of scripts that scans every IP
           | address for WordPress plugin vulnerabilities.
        
             | Dunedan wrote:
             | > Caching solves only the performance problem, which in my
             | mind is the least compelling reason to go for static site.
             | 
             | One the other hand there are compelling reasons for not
             | going with a static site as well.
             | 
             | Try getting non-technical users to write the markup for
             | their posts by hand without a WYSIWYG editor. Or try to
             | integrate features like comments with a static site without
             | using a third-party service.
             | 
             | > If your wp-admin routes are still accessible to the
             | public internet, then you are still at risk for broken
             | plugins causing a hack. You have to both cache all static
             | directories and firewall the actual server if you want to
             | avoid being hacked by one of the thousands of scripts that
             | scans every IP address for WordPress plugin
             | vulnerabilities.
             | 
             | That's a risk you have with every internet facing software.
             | Yes, static sites are great, because they greatly reduce
             | the attack surface, but there are reasons why not every
             | website is a statically generated site. As the comment
             | which lead to that thread already mentioned it's quite easy
             | to reduce the risk by keeping the number of plugins as
             | small as possible.
             | 
             | I run several websites powered by Wordpress since more than
             | 15 years and so far didn't have any security incident with
             | them.
        
           | Neil44 wrote:
           | You would have to configure that carefully so that for
           | example you didn't cache shopping baskets.
        
             | Dunedan wrote:
             | As shown in the linked guide you'd configure that based on
             | something like an application specific cookie, which is
             | probably required for the shopping basket in the first
             | place anyway. I believe solutions like WP Super Cache
             | handle that the same way, but I might be wrong about that.
        
       | vibdev wrote:
       | Love the McAfee Secure Logo at the bottom of the AccessPress
       | site, that's how you know you can trust them.
        
       | shadowgovt wrote:
       | I have thought about moving my personal blog onto something that
       | isn't someone else's service. But every time I think about
       | running my own blog server, stories like this come along.
        
         | yosito wrote:
         | Why not move your personal blog to a static site generator?
        
           | adam12 wrote:
           | Not OP, but one thing that gets in the way for me is user
           | comments.
        
             | drexlspivey wrote:
             | Check out https://utteranc.es/
        
             | sneak wrote:
             | Disqus exists for this reason.
        
         | leppr wrote:
         | You don't need to use WordPress where themes can apparently run
         | server code. Plenty of simpler solutions like Gatsby and
         | others.
        
           | noahtallen wrote:
           | A theme is server code :) Since WordPress is PHP, rendering
           | the front end is done in PHP on the server. A theme writes
           | PHP to render custom templates, which (on top of styles) is a
           | large part of what themes do in WordPress.
           | 
           | This is changing to an extent with the Full Site Editing
           | project, but themes and plugins are both very powerful and
           | flexible in WordPress, which has in part led to its massive
           | success.
        
         | wanderingmind wrote:
         | Setup your blog in Github pages with Jekyll[0]
         | 
         | [0] https://docs.github.com/en/pages/setting-up-a-github-
         | pages-s...
        
           | turminal wrote:
           | Github is not their own server.
        
         | b0ner_t0ner wrote:
         | https://wp2static.com/ or https://www.strattic.com/
        
         | sgallant wrote:
         | This is 100% possible without a server. Your repo can be your
         | database if you run it statically with something like Hugo (a
         | single binary with no dependencies). Store your content in your
         | own repo in Markdown files (or something similar, like MDX) and
         | host it on Netlify, Vercel, AWS, etc.
         | 
         | If your site has 10K posts and you don't want to deal with long
         | build times, use Next.js with ISR (make some high traffic pages
         | static, others dynamic (server side rendered)).
         | 
         | As the founder of Forestry.io and Tina.io, I'm biased about a
         | content editing UI, but there are many options if you want a
         | GUI on top of your content files.
         | 
         | You got this.
        
           | hanklazard wrote:
           | Agreed! I've used Hugo + Netlify for the last few years,
           | really like it. I'm not a big blogger, but it would be easy
           | to run a blog with this setup.
        
             | sneak wrote:
             | You don't need Netlify for this; all you need is a git repo
             | somewhere and CI.
             | 
             | CI can do the build, and the last step of CI can be ftp,
             | rsync, scp, or whatever. It's just static files, normal
             | hosting anywhere is fine.
        
               | viraptor wrote:
               | There's usually a huge difference in access latency
               | though. The usual cheap ftp hosting means a choice of
               | whether you want to be 200ms away from the US or from
               | Australia.
        
               | [deleted]
        
         | sircastor wrote:
         | For all the Hugo and Jekyll and other static site generators
         | mentioned, you can run Wordpress locally and have it generate
         | static output. Granted, it would be with a plug-in, but
         | presumably not accessible from the outside world.
        
           | withinboredom wrote:
           | You can use php-fpm and nginx's built-in fpm cache. No plugin
           | required.
        
         | lolinder wrote:
         | As others have said, static site generators are _super_ easy to
         | set up, and for a blog you 'd be able to do basically
         | everything in Markdown. You can also very easily include
         | Netlify CMS or similar for a GUI editor (which will make
         | commits directly to your repo).
         | 
         | I'd recommend at that point just using GitLab or GitHub pages
         | as others have suggested, but if you do want to move completely
         | off of other people's services, it's much simpler to set up
         | nginx or Apache to serve static files than it is to safely host
         | a WordPress instance.
        
           | systemvoltage wrote:
           | Or you can use any CMS or blogging software and just use
           | Cloudflare, add a rule to cache everything. Done.
           | 
           | I use Ghost + Cloudflare.
        
             | lolinder wrote:
             | That's a pretty good option, as long as your CMS is
             | thoroughly firewalled and only accessible from your
             | computer and Cloudflare. If you can reach the admin console
             | from the wider internet then you haven't solved the real
             | problem with WordPress, which is security not speed.
        
               | systemvoltage wrote:
               | Good point. Cloudflare tunnel or Strict Origin-CA on
               | Cloudflare proxy settings. It will require setting up SSL
               | on the host though.
               | 
               | It is not for security but for occasional spikes of
               | traffic. Nothing says we can't use static-site-generator
               | + Cloudflare. Even better.
        
           | pmlnr wrote:
           | SSGs are not "super easy" for non-devs. What's super easy is
           | things like https://www.silex.me/ or, with more
           | functionality, https://pinegrow.com/
        
             | john-doe wrote:
             | https://getpublii.com/ comes to mind too.
        
             | lolinder wrote:
             | Hugo or Jekyll should be super easy for anyone who's
             | seriously considered hosting their own WordPress instance,
             | like OP is. If setting up a static site generator is too
             | difficult, they _definitely_ shouldn 't be running
             | WordPress themselves.
        
               | temp8964 wrote:
               | The easy Hugo or Jekyll setups do not match the features
               | of WordPress. So they are not easy.
        
               | jiggunjer wrote:
               | What features are the main considerations?
        
               | temp8964 wrote:
               | Like setup categories and tags, themes, url structure,
               | etc. without needing to read the documentation?
        
               | lolinder wrote:
               | I'd count all of those in the "easy for developers"
               | category, as long as you're willing to read
               | documentation. It's 1-2 lines of config for any one of
               | those, and the config in question is at the very front of
               | the doc pages.
               | 
               | If you're unwilling to read documentation, then yes,
               | you're probably better off sticking to Squarespace or
               | WordPress.com
        
               | sneak wrote:
               | Doing everything in a web browser without editing local
               | files, mostly. "Open a text editor" or "git commit" are
               | enough to put off people who don't think of themselves as
               | computer people even though complexity wise they are no
               | different than WP, simply because you gotta leave the
               | browser.
        
               | lolinder wrote:
               | Netlify CMS is pretty easy to set up and has all of the
               | basic features that you need for a simple blog.
               | 
               | And again, I would never recommend a static site
               | generator to someone who doesn't think of themselves as a
               | computer person. The context in which this conversation
               | started was someone who was seriously considering hosting
               | their own WordPress instance. I dearly hope that they
               | think of themselves as a computer person.
        
               | temp8964 wrote:
               | I am a programmer, but I don't have patience to read
               | through SSG documentation to setup a basic website.
        
               | magicalhippo wrote:
               | It's been a wee bit since I last looked, but for me I
               | want these "out of the box":
               | 
               | - Good support for posting source code from various
               | languages, both inline and in blocks, with syntax
               | highlighting.
               | 
               | - Zero-effort image posting ala WordPress, ie with
               | automatic down-sizing of the inline image if needed (in
               | these days ideally multi-resolution).
               | 
               | I imagined these were quite basic needs, but I've been
               | disappointed each time I've gone looking. Been a year
               | since last time though.
        
               | lolinder wrote:
               | Hugo, at least, has built-in syntax highlighting (both
               | block and inline) and at a glance it looks like Jekyll
               | does, too.
               | 
               | Netlify CMS has zero-effort image posting (saves to your
               | repo's static folder). I'll grant that it doesn't do
               | automatic downsizing, though Netlify as a CDN does.
        
               | viraptor wrote:
               | You're assuming that the person running the instance and
               | writing content is the same. There are WP instances
               | backing up serious business where people who don't know
               | what CMS even means successfully edit content every day.
        
               | lolinder wrote:
               | Context matters. I recommended a static site generator to
               | a very specific person. Here's the comment I initially
               | replied to:
               | 
               | > I have thought about moving my personal blog onto
               | something that isn't someone else's service. But every
               | time I think about running my own blog server, stories
               | like this come along.
               | 
               | So... yes. I was assuming that OP was going to both be
               | the person running their _personal_ blog and writing on
               | it, and I was assuming that OP is pretty technically
               | competent if they were seriously considering running
               | their own blog server.
        
         | z3t4 wrote:
         | Anything that can be written to and executed from the Internet
         | will be a security issue. The only thing your public facing web
         | server should be able to write to is the log file.
        
         | 0xbadcafebee wrote:
         | Why do you not want to use somebody else's service?
        
           | shadowgovt wrote:
           | For me, mostly control. I've been writing my blog in Markdown
           | for ages, but Blogger only natively supports its bad WYSIWYG
           | editor or pasting raw html. I've decided the friction in
           | pipeline is enough that I kinda want to cut it out of the
           | loop.
        
         | [deleted]
        
       ___________________________________________________________________
       (page generated 2022-01-23 23:02 UTC)