logoalt Hacker News

mirashiitoday at 5:23 AM4 repliesview on HN

The "surprisingly secure" WordPress just had a unauthenticated RCE earlier this year. Just simplifying isn't going to be enough.

https://nvd.nist.gov/vuln/detail/cve-2026-63030


Replies

ricardobayestoday at 6:26 AM

If that's your benchmark for being unsecure, then React is unsecure too.

https://react.dev/blog/2025/12/03/critical-security-vulnerab...

show 1 reply
wolvoleotoday at 8:33 AM

WordPress and secure don't go together in the same sentence.

I mean the base is fairly secure if you religiously update it, but the problem is you won't avoid using plugins whose security is much more hit and miss, unless you are using the most basic blog site imaginable.

pmlnrtoday at 5:58 AM

"First step"

Nobody said it's enough, but it's a start.

spiderfarmertoday at 5:34 AM

Plus, how secure are the plugins?

show 1 reply