4 ms·
Definitely not. Wordpress plugins are the source of exploits in the Wordpress ecosystem -- it's very very rarely the Wordpress core itself.
by dotty- 4y ago
Definitely not. Wordpress plugins are the source of exploits in the Wordpress ecosystem -- it's very very rarely the Wordpress core itself.
- bombcar 4y agoAnd it's almost always older versions of plugins that are vulnerable; however, at some point a plugin update will break the website and then you don't upgrade because there's more important things to do ...
- apercu 4y agoIt's the dependency loop of Wordpress really - people can't update the core because their plugins don't work with new core (yet, sometimes never), so their (outdated) core remains an exploit.
- SoftTalker 4y agoNot strictly a Wordpress issue, this happens with any CMS that allows third party modules (Drupal, for one, as I know from direct experience).
- tyingq 4y agoYes, though the plugin system itself has really no rails at all. Any plugin can do anything.
- n3storm 4y agoThe core main task is execute millions of actions/hooks offered without any control to be exploited by plugins. So "not hacking the core of wp" is really "hacking the core of wp"