today at 6:06 PM
These are the reason, why every easily reachable web server will be spammed with /something/something.php?somearg=someval. If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates. Maybe right after MS Teams or Sharepoint or some stuff like that.
today at 6:28 PM
> WP would surely be among the top candidates
And its closely related cousin, Joomla.
today at 6:59 PM
Joomla makes WP look like Fort Knox.
today at 6:54 PM
TBF, some of it is structural: if you're the most popular anything on the internet, you'll be the most attacked and the most exploited, and hence the most exploitable.
today at 7:20 PM
That's not really true.
today at 7:29 PM
nginx serves a third of web traffic.
today at 7:04 PM
The access log of public http servers is truly interesting to watch.
You know that the scripts doing it are optimized for success rate, so the types of requests they send give you an impression of what's actually out there.
It's clear to me that once we finally achieve rogue AGI, it is going to propagate through unpatched WordPress WooCommerce instances.
today at 7:28 PM
Not success rate per request though.
today at 7:47 PM
to be fair it is one of the top CMS's on the web (probably won't be in 2027) and its PHP / Mysql which in history have been very exploitable.
today at 7:12 PM
If I had to guess, which software on the web has been the most exploitable over all of the web's history, WP would surely be among the top candidates.
People on HN love to talk smack about WordPress. After all these years, it's as much a reflex as shouting "walled garden!" every time there's an Apple story.
Yet some of the biggest web sites on the internet run WordPress, and more importantly, some of the biggest hacking targets on the internet run WordPress.
Prime example: whitehouse.gov.
If you know what you're doing, WordPress fine. The same is true with every other piece of technology out there.
But people on HN like to lump the good in with the bad because everything is binary.
today at 7:38 PM
> If you know what you're doing, WordPress fine
If you know what you're doing, a loaded gun without a safety is fine, too. But you have the option, why not pick the unloaded one with a safety mechanism?
today at 7:31 PM
> If you know what you're doing, WordPress fine.
Probably true, but for whatever reason Wordpress seems to attract an awful lot of people that do not know what they are doing
today at 6:33 PM
I am so happy that I asked Codex to rewrite our website as Hugo templates which allowed us to statically host it and get rid of Wordpress. So much stress gone!
today at 7:48 PM
This thread is fucking unhinged
today at 7:10 PM
You can make the most intricate drag and drop admin interfaces to allow the editor to customize everything, and they will still call you to put up every post, so might as well go static
today at 7:42 PM
Is there a good replacement for wordpress comments? That's the one thing holding me back from porting at the moment.
today at 6:53 PM
When I finally got approval to rewrite the company blog from Wordpress into something that was mostly static, it was the best week. I used PHP to do mobile/desktop and language selection, because PHP is pretty useful, and it can be pretty fast and secure if you only do simple things.
Never had to worry again about sequencing updates where the update changed the database schema and I had a cluster of 6 web servers. Never had to worry anymore about long ass load times because the web servers were in 3 colos and wordpress wouldn't play nice with local read only mysql replicas. No more worries about why pingbacks and comments keep showing up in the database even those those features were turned off; at least they weren't showing up in a moderation queue, but still.
today at 6:44 PM
Sorry in advance if you were joking, but for readers who aren't in the know: Hugo had, in fact, two 9.3 CVSS vulnerabilities just 11 days ago...
https://app.opencve.io/cve/CVE-2026-89259
https://app.opencve.io/cve/CVE-2026-89258
today at 6:54 PM
To be clear, those are CVEs in the tooling, not in the generated static sites. Not great, but very different from this WordPress CVE
today at 6:18 PM
The patch (identified from https://github.com/WordPress/wordpress-develop/compare/7.1.1...):
https://github.com/WordPress/wordpress-develop/commit/9c4e85...
today at 7:08 PM
It's crazy to me that WP still doesn't make use of proper function type declarations, 11 years after they were added to PHP.
today at 6:48 PM
WordPress really is a piece of garbage software, and if you've ever developed plugins for it it is soooo apparent.
The documentation is a perfect reflection of the absolute mess of spaghetti code that it is, half of the methods that you will use constantly when developing plugins are undocumented, even untyped. It's literally unusable.
I know WordPress is good thanks to its ecosystem, but really, really, do NOT use it.
today at 5:18 PM
Ironically, this 9 years old comment on the official documentation page of one of the affected functions perfectly describes both the nature and remediation of this major security flaw:
> Paul Ryan 9 years ago
> Note that locate_template() does not prevent directory traversal attacks, so if you’re passing a user-provided template name to the function, be sure to verify that it’s from one of the three appropriate locations (active theme directory, parent theme directory, or /wp-includes/theme-compat/ directory).
https://developer.wordpress.org/reference/functions/locate_t...
today at 5:25 PM
Ahahah I remember to have patched themes for clients by hand, years ago. A different time, where a core team would for whatever reason leave security holes around to be sure you need three frameworks around their pile of dung code.
today at 5:10 PM
hmm, this may be why i just saw an unexpected update to a very old theme.
today at 6:26 PM
It's not clear to me: do we need to both apply the patch _and_ check if our themes are vulnerable, or just apply the patch?
Edit: looking at the patch itself it looks like it fixes the root cause and so it shouldn't matter what themes are doing themselves. But possibly I'm reading it incorrectly.
today at 4:58 PM
pearcmd.php must exist, and register_argc_argv must be on, not common with hosting providers. But I am assuming the other themes and meeting conditions possibly affect a lot of WordPress sites.
today at 5:16 PM
As the article points out, one issue is that the official Docker container for PHP has this configuration.
However at least in principle all of the affected versions [0] could be automatically updated. Not sure if they have set it to auto-update as far back as 4.7 though.
[0] except 4.9.3 which has a bug in its automatic update mechanism.
today at 5:19 PM
pearcmd and register_argc_argv are just examples. get_page_template was unsanitized in some themes, that's the flaw, you could then combine it with one of a million unauthorized file upload in wordpress plugins to try and eval code. An attacker would like to use upload + this chain of requires (instead of just uploading a php) because of hardened configuration and the pwn can go unnoticed in the logs.
Also, with pearcmd (if you can get to that, there's no open_basedir) and containers a novice sysadmin will publish insecure sites.
today at 5:02 PM
[flagged]
today at 5:20 PM
Not sure if it’s a couple. Devs routinely make heavily edited copies of the core themes so there will be many, many unpublished themes that use the “page-“ prefix for templates; it was (is?) a reasonably common convention.
(No particular disagreement with the rest of your comment though)
today at 5:13 PM
This score specifically means that given some specific conditions, anyone can execute code over the network on a vulnerable WordPress setup. Is this not true?
today at 5:19 PM
I'm not saying that the vulnerability isn't severe or important to people running Wordpress, only that CVSS scores are literally a Ouija Board that can come out to whatever the user wants them to.
today at 6:05 PM
Yeah give me a vuln and I can make it anything between a 2 and 8 quite easily. I routinely see 10s that are "Critical 10.0 CVE (but only if you're using X language with X setting changed from default, and the attacker can MiTM your traffic)"
today at 5:33 PM
> CVSS scores are literally a Ouija Board that can come out to whatever the user wants them to.
Not really. They are very good at describing the technical impact. Sometimes pre-condition is very rare and that reduces overall likelihood but for those few it applies, the impact still could be catastrophic. Who wants to risk it if whole business could go down?
today at 5:39 PM
So if I get a 9.8 that doesn't apply to my usage, what is the CVSS score doing for me?
today at 5:48 PM
Published CVSS is a base score that gives you a hint of how important the analysis of a vulnerability is to prioritise the patching or mitigation. What you see on websites is only ever the base spiciness so to speak. If you have for example wordpress only running in an isolated environment behind internal firewall rules you‘d downgrade it accordingly. It’s a imperfect metric but so far the best we have to signal priorities. It’s all described in its spec that no one seems to read and websites also communicate it badly.
today at 7:11 PM
CVSS is impossible to communicate effectively. We don't need a metric; I'm already going to have to read and assess the vulnerability to decide how I actually want to assess the risk given my infrastructure, so the number's not doing me any good.
This isn't just a CVSS issue: there have been a variety of attempts to reduce a risk score down to a single general number and they all end up as somewhere between marketing material, scare tactic, and junk science.
today at 7:39 PM
> We don't need a metric; I'm already going to have to read and assess the vulnerability to decide how I actually want to assess the risk given my infrastructure, so the number's not doing me any good.
Would you say that vulnerability with CVSS score that points to low is equally important to verify and take care of than CVSS which points to critical?
today at 5:57 PM
Yes. It's amazing how supposedly security professionals only take the base score "as is" and never adjust.
Many GUI CVSS calculators exist just for this, it takes a minute to requalify a vuln and adjust its CVSS based on your specific environment.
This one for example is pretty basic but works well: https://www.first.org/cvss/calculator/4.0
> These metrics enable the analyst to customize the CVSS score depending on the importance of the affected IT asset to a user’s organization, measured in terms of complementary/alternative security controls in place, Confidentiality, Integrity, and Availability. The metrics are the modified equivalent of base metrics and are assigned metric values based on the component placement in organization infrastructure.
today at 5:53 PM
You need to reason about both probability and impact, not one or the other. In your example, it just means that the probability is very low, perhaps even down to 0 in your specific case. But even at a low probability, the impact of the vulnerability remains very high so it helps you reason about it.
For example, you might react differently to these scores:
- <8/10: check that your systems are indeed secure
- 8.6/10: check that your systems are indeed secure and tell your junior analyst to train on creating a custom monitoring rule for that attack and follow-up with you
- 9.8/10: double-check that your systems are indeed secure, ensure that if you had a hole another security layer would have caught it (if not, that's a problem!), set up a honeypot to get some info on the assholes that have repeatedly attacked you lately and will undoubtedly try to 0-day you in the next few hours, etc.
today at 5:47 PM
today at 5:40 PM
My assumption is that any Wordpress setup whatsoever allows anyone to execute code remotely.
today at 6:00 PM
Indeed, it's a foothold into a network.
today at 5:13 PM
> This is a somewhat situational Wordpress RCE that impacts only a couple themes. reply
That is dangerously incorrect, a whole lot of themes are vulnerable. The main pre-condition, "presence of a top-level directory named 'page-xxx' like 'page-templates' in the theme's directory" is actually an official recommendation in the WordPress documentation.
See here: https://developer.wordpress.org/themes/classic-themes/templa...
> As discussed in Organizing Theme Files, WordPress can recognize page templates stored in the theme’s root folder or in a first-level subdirectory of the theme folder. *The page-templates/ folder is a common convention* for organizing global page templates, but it is not required. Page templates can also be stored in other first-level subdirectories, such as templates/ or page_templates/.
today at 5:56 PM
Yeah not sure why you’re being downvoted when the built in themes are vulnerable as is the default docker image pre php8.5 which a lot of people use as a base and I bet a lot of hosting providers use as well behind the scenes.
today at 6:30 PM
It's crazy how many users are standing by this take. Not only is a 9.8 CVSS critical, even if it doesn't affect your config, you should trash any dependency that has so many 9+CVSS vulns that you become numb to them.
When you use a dependency and a 9+CVSS vuln comes out, you read it and respect it. If you come to the conclusion that CVSS don't mean anything because there's just so many vulns, that's saying something of the dependency and your security posture.
Burn Wordpress with a flemmenwerfer, or build a hard virtualization layer around it, give it its own scoped certs, your Wordpress things will get hacked, especially if they use plugins.