4 ms·
In the past, I have worked in a couple different multi client firms that handled a lot of WordPress installs and I think every single one of them used ACF. It's
by devmor 3y ago
In the past, I have worked in a couple different multi client firms that handled a lot of WordPress installs and I think every single one of them used ACF. It's also had many major security issues like this.
I vaguely remember another one that was nearly as ubiquitous and constantly causing people to get hacked - had a very generic name like "Contact Form 2000" or something.
- gjsman-1000 3y agoContact Form 7?
- devmor 3y agoThat's the one! I had the number wrong.
- chiefalchemist 3y agoTo your point "The vast majority of bloggers and small business owners that run WordPress sites … are not cybersecurity experts," Ellis said. That audience is also unlikely to use ACF.
- devmor 3y agoNo, they are quite likely to be using ACF... and not even know that they are using it. The majority of these folks pay someone to set up their website and then never touch it again until something breaks. This was the primary reasoning behind WordPress forcing automated updates.
- Dalewyn 3y agoThe tech industry more or less refuses and denies with the fury of a thousand chimpanzees the reality that common men only see computers and the things they provide as fixed appliances.
- kyriakos 3y agoMost wordpress sites are setup by web "designers". Install as many plugins needed to get the job done along with a theme. Usually follow tutorials for most things which are often outdated. If the tutorial suggests ACF then ACF is installed. Unsuspecting client recieves site with zero knowledge of what they are getting into. Especially a problem if any customization is made to plugins blocking them for automatically updating.
- chiefalchemist 3y agoI do agree. ACF is indicative of site owner hiring someone else to do the design / build. The rest, I see it different. Most WP sites are self-setup (read: for "free") by the site owner. ACF has 2M installs. That's a fraction of total WP sites. Therefore, I conclude most WP site aren't setup by "designers".
- Ayesh 3y agoI occasionally working with WordPress sites, and I personally find ACF plugin as a smell when someone tries to bend WordPress into what it already is not. Pretty much 100% of compromised WordPress sites I get are caused by a plugin like this, be it either a configuration issue or a vulnerability in code.