7.0.2 got released on Friday. Exploits are already happening. People reporting hacks
PSA WordPress Core had Critical Vulnerability. Patch released on Friday. Immediately update
https://slcyber.io/research-center/wp2shell-pre-authentication-rce-in-wordpress-core
21 Comments
CausticFlames@sopuli.xyz · 27 pts · 35d
Friendly reminder to anyone who cares enough that you can still use WordPress to make your site with all your fancy plugins and layouts, and then export that to a static site for hosting. No need to actually host Wordpress itself that way you avoid nearly all of this BS.
LunarLoony@lemmy.sdf.org · 12 pts · 34d
Not a bad idea. How would one do this?
CausticFlames@sopuli.xyz · 12 pts · 34d
Simply Static is currently the most actively maintained solution, as a plugin for wp:
https://docs.simplystatic.com/category/6-user-guides
There is also WP2Static, which is a very long standing project: https://github.com/elementor/wp2static
yuman@programming.dev · 2 pts · 34d
this thing here. I've dramatically reduced support work at two shops I've set this up for. incidents went from from coupla times a month to once a year. not to mention - you don't need no VPS no more, don't need no database, nothing, the simplest web hosting will do and it's very cache friendly.
ThanksObama@sh.itjust.works · 24 pts · 35d
Correction: WordPress IS a critical vulnerability.
9point6@lemmy.world · 16 pts · 35d
https://www.wordfence.com/threat-intel/vulnerabilities
The CVE list always cracks me up, there's like tens daily
chronicledmonocle@lemmy.world · 6 pts · 34d
JFC I thought you were exaggerating.
SreudianFlip@sh.itjust.works · 5 pts · 35d
Anyone who hosts websites can check the logs and see the bots hammering away at wp/admin primarily, even if you are not running any WordPress. Low hanging meat? Fresh fruit?
ctenidium@lemmy.world · 1 pts · 34d
Elementor makes it worse though.
Marthirial@lemmy.world · -2 pts · 35d
I have developed and hosted over 760 WP sites since 2006 and have never been hacked. Ever.
Mediocre craftspeople blame their tools.
kungen@feddit.nu · 12 pts · 35d
I've driven a poorly designed car without many safety features for years, and I've never flown through the windshield, ever.
loo@lemmy.world · 7 pts · 35d
Glad you got lucky. But a tool having one critical vulnerability after another has nothing to do with mediocre craftsmanship and blaming admins for getting hacked after updating their software is nothing but disrespectful and condescending
LunarLoony@lemmy.sdf.org · 5 pts · 34d
How do you know?
genzboomer@lemmy.zip · 5 pts · 35d
Professionals are never cocky. Cocky comes back to bite.
lIlIlIlIlIlIl@lemmy.world · 3 pts · 35d
It’s time to ditch WP if you haven’t already
non_burglar@lemmy.world · 7 pts · 35d
It was time in 2013.
kohlenstoff@feddit.org · 1 pts · 34d
What would you recommend as an alternative for the non-technical inclined users who want to have a public website?
non_burglar@lemmy.world · 1 pts · 34d
Is this a trick question?
Websites are complicated. Easy, secure, cheap: pick two. There is no such thing as a universally easy, secure and cheap solution, or else we would always be using it.
Assuming you want secure and easy, I would suggest you pay someone who knows what they're doing.
kohlenstoff@feddit.org · 2 pts · 34d
No, not a trick question at all.
I know what I am doing but people I work for do not, therefore my question for an alternative where these people can write text on a simple website in a WYSIWYG editor. Going by your comment you haven't found one either which makes WP sadly the only option for this specific use case.
non_burglar@lemmy.world · 3 pts · 33d
I haven't found one, no. I just use markdown and a static HTML site generator.
xzinik@feddit.cl · 3 pts · 34d
thank god i was able to convince my boss to let go the old wordpress site and only serve static pages when he wanted to have a brand new design, its been about 2months with the new design