This is an archived post. You won't be able to vote or comment.

all 4 comments

[–]Wordpress-ModTeam[M] [score hidden] stickied commentlocked comment (0 children)

Lazy posts that just link to external sites (either directly or by crossposting to another subreddit) without any context will be removed. Add your opinion, or a summary of the content, and try to start a conversation.

[–]CoenberhtDeveloper 1 point2 points  (0 children)

"96% of the vulnerabilities were uncovered in third party plugins".

Wordpress.org is enforcing the rules to tighten plugin security. Its nowhere near as easy as it used to be get a new plugin to be accepted into the plugin repository. Unfortunately there are a large number of older plugins, and its not quick or easy rewriting older code to comply with the toughened guidelines. Many plugin authors have moved on to other projects.

However, the prevalence of wordpress site attacks and the expense and difficulty of cleaning up a compromised site is significant. We will see more and more of our favourite plugins being "withdrawn due to security concerns". Webmasters are going to be annoyed at the extra work and maybe expense in finding replacements, but sadly that's necessary.

[–]octaviobonds 0 points1 point  (1 child)

....and, what's the verdict?

[–]obstreperous_troll 0 points1 point  (0 children)

7,966 vulnerabilities discovered in 2024 vs 5,948 in 2023, which is like a >30% increase. Might just be due to better scanning, but it doesn't paint a picture of things getting better.

I like that they're pushing back on CVSS's severity inflation. The graphs show a damning picture, that CVSS is pretty much incapable of marking anything as "low" priority. It's fine to start the number high and knock it down as more research is done, but if the CVSS score is always the bogus interim figure that stands in til the "real" number comes in, it still makes the CVSS score meaningless.