20 Jul 2016

Poor Security Journalism Doesn’t Help To Improve Poor State of WordPress Plugin Security

We think it would be fair to say the state of WordPress plugin security isn’t good these days. As an example, we could point to how often we are often we have been finding vulnerabilities in the current versions of plugins based on what looks to be hackers already discovering that vulnerability or some other security vulnerability in a plugin and then probing for usage of the plugin so that they can start exploiting it. Good journalism that sheds light on the very real security problems might go a long way to moving things toward improvement. Unfortunately so much of security journalism, whether WordPress related or otherwise, is quite bad. Due to our monitoring of news coverage of security issues in WordPress plugins, to make sure we are providing our customers the best data on plugin vulnerabilities possible, we run across a lot of the bad coverage.

One example we thought was worth highlighting since we can use it provide some useful information, is an article put out today on The Register, WordPress admin? Thinking of spending time with the family? Think again. [Read more]