Earlier quoted context omitted.
> Where is the CVE? What risk is there continuing to use the original plugin? Here’s the diff showing what has changed: https://plugins.trac.wordpress.org/changeset?new=3167679%40a...
For those reviewing the changeset: There are two places where they read a value directly from $POST into an $args array. There is no validation applied, which means an attacker can inject whatever value they wish.
WordPress.org's latest move involves taking control of a WP Engine plugin
41–50 of 222 posts
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#42The appropriate twist here would be to have WPEngine find a trusted third party (one or more), start a foundation together and successfully fork wordpress.
Edit: That attracted a lot of downvotes. I was giving my option in response to the parent comment. In my option Automattic would be happy if they forked it.
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#43I just cancelled my ACF subscription as it's up for renewal in 30 days. I'll wait and see how the dust settles.
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#44Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#45Earlier quoted context omitted.
At this point I wouldn't be surprised if he'd had secured funding for a new CMS platform startup and is secretly working on it. He seems absolutely hellbent on assuring nobody should use Wordpress.
After this, who would trust his second try?
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#46The appropriate twist here would be to have WPEngine find a trusted third party (one or more), start a foundation together and successfully fork wordpress.
I think Matt would be quite happy with that. His issue is WP Engine not contributing to WordPress. If they decide to maintain a fork and infrastructure, they won't be freeloading anymore. Edit: That attracted a lot of downvotes. I was giving my option in response to the parent comment. In my option Automattic would be happy if they forked it.
Is that an option btw? I.e. is it possible to offer hosting with seamless migration from wordpress.org?
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#47Mullenweg is hijacking existing users with supply chain attack.
> supply chain attack. Where's the "attack" part? I thought that was a crucial part in the definition
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#48Earlier quoted context omitted.
The author of a library has lost all control over the codebase, and a third party is now making changes to it. That's pretty much the textbook definition of stage one of a supply chain attack. Considering what Matt has already done, it wouldn't even remotely come as a surprise if a future ACF update would, say, brick all WP installations using ACF on a WP Engine host.
It's like claiming going to the bank is stage one in a robbery. So if you go to the bank you're a thief. WordPress have the rights, just like the responsibility and possible liability of everything distrubted on their platform.
At this stage no attack has happened(but can happen)
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#49They either have some of the best or worst legal counsel; or they just ignore the legal counsel.
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#50Earlier quoted context omitted.
It's like claiming going to the bank is stage one in a robbery. So if you go to the bank you're a thief. WordPress have the rights, just like the responsibility and possible liability of everything distrubted on their platform.
It's more like gaining backdoor access to the bank's server. At this stage no attack has happened(but can happen)