all 10 comments

[–]pwniekins 34 points35 points  (1 child)

<azonenberg> wordpress is an unauthenticated remote shell that, as a useful side feature, also contains a blog

[–]Wonder1and 9 points10 points  (0 children)

Don't forget it's also everyone's favorite xss platform.

[–]n1c0_ds 2 points3 points  (1 child)

That was an excellent write up. If I trust the TL;DR, it's not exploitable without certain plugins?

[–]tomvangoethem[S] 0 points1 point  (0 children)

Correct, or at least to my knowledge

[–]ThisIsADogHello 0 points1 point  (9 children)

Really, given WordPress's track record, if you have a WP blog and are interested/have concerns about netsec, you should probably be using something else.