It’s Not WordPress. It’s the Plugins.
Stefano Marinelli @stefano@journal.bsd.cafe
<p>After managing hundreds of WordPress sites over the years, one thing is clear: the core is solid – it’s the outdated, poorly written plugins that open the doors to attacks. At OSDay 2025, I attended a talk that confirmed this and shed light on a massive bug bounty hunt that closed nearly 1,000 vulnerable plugins.</p>
Read more →