Wednesday, June 27, 2018

New comment by Fellshard in "Unpatched WordPress vulnerability allows code execution for authors"

Except WordPress is almost completely founded on its plugins, so that's a non-trivial consideration. Specifically, if WordPress cannot provide proper abstractions, sandboxing, and protocols for plugins to be secure by default, the issue could be greatly reduced. As-is, its model both encourages such flaws to be included and provides its non-technical users with no viable way to identify which are likely to be vulnerable plugins.

from Hacker News: "WordPress" comments https://ift.tt/2MuD3ll
via IFTTT

No comments:

Post a Comment

How English clubs got smart to dominate this season's Champions League

Premier League clubs always had the money, but now they also have the know-how they have dominated this season's Champions League. fro...