4 ms·
The "surprisingly secure" WordPress just had a unauthenticated RCE earlier this year. Just simplifying isn't going to be enough. https://nvd.nist.gov/vuln/deta
by mirashii 25d ago
The "surprisingly secure" WordPress just had a unauthenticated RCE earlier this year. Just simplifying isn't going to be enough.
https://nvd.nist.gov/vuln/detail/cve-2026-63030 https://nvd.nist.gov/vuln/detail/cve-2026-63030
- spiderfarmer 25d agoPlus, how secure are the plugins?
- m_mueller 25d agoWP plugins are why I banned it everywhere. Last time I used it was many years ago, so not sure it still applies, but back then even caching was done in a plugin, without which it was unusably slow… just no.
- pmlnr 25d ago"First step" Nobody said it's enough, but it's a start.
- ricardobayes 25d agoIf that's your benchmark for being unsecure, then React is unsecure too. https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components https://react.dev/blog/2025/12/03/critical-security-vulnerab...
- mirashii 25d agoI would put both of those projects in the category of things I wouldn't call remarkably secure, yes. To be remarkably secure, these projects would need to not have these kinds of defects, despite the combination of being written in languages have that have a long track record of footguns and lack of initiatives to fix them (proposal-symbol-proto, and PHP's list is too long to even start) and being themselves ecosystems with questionable track records on security in the related areas (Look at $wpdb in 2026, or overall code quality and willingness to modernize, or the entirety of the model of RSC for things that are just going to nearly guarantee you punch all kinds of holes on accident).
- wolvoleo 25d agoWordPress and secure don't go together in the same sentence. I mean the base is fairly secure if you religiously update it, but the problem is you won't avoid using plugins whose security is much more hit and miss, unless you are using the most basic blog site imaginable.