Earlier quoted context omitted.
> Where is the CVE? What risk is there continuing to use the original plugin? Here’s the diff showing what has changed: https://plugins.trac.wordpress.org/changeset?new=3167679%40a...
wow, they deleted 300 lines, many giving credit to others, just to replace it with > Security - ACF defined Post Type and Taxonomy metabox callbacks no longer have access to $_POST data. (Thanks to the Automattic Security Team for the disclosure) If I was on that security team, I would be livid they used my team's name on this behavior. If this was done by that security team, their ethics are disgusting, and likely n…
WordPress.org's latest move involves taking control of a WP Engine plugin
61–70 of 222 posts
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#62So, ACF injected notices into everyone's dashboards to push their own legal agenda. It’s a move that reeks of self-interest more than community benefit. While everyone’s ready to grab their pitchforks at Matt, this actually sounds somewhat reasonable. Still, given its impact, this could easily be seen as a breach of trust. Definitely a move that's going to stir the pot.
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#63So, ACF injected notices into everyone's dashboards to push their own legal agenda. It’s a move that reeks of self-interest more than community benefit. While everyone’s ready to grab their pitchforks at Matt, this actually sounds somewhat reasonable. Still, given its impact, this could easily be seen as a breach of trust. Definitely a move that's going to stir the pot.
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#64Earlier quoted context omitted.
Yeah, but pretty sure some of the employees/volunteers are in on it or "just following orders."
Yes, no one stopped the co-funder and it's unlikely he did the fork and the change of ownership only by himself. Other people at Automattic are responsible too.
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#65Earlier quoted context omitted.
> Where is the CVE? What risk is there continuing to use the original plugin? Here’s the diff showing what has changed: https://plugins.trac.wordpress.org/changeset?new=3167679%40a...
I do see various security fixes in that patch, but most of the changes are removing references and code for a "pro" version of the plugin. I'm guessing the WP security team has been pentesting any WPEngine code they could get their hands on to find an excuse to make all of these changes. The security issues do look bad (once again proving that WordPress' worst vulnerabilities come from the plugins they install) but I…
The WP security team may have just backported the fix, even using the same line in their changelog [1].
[0]: https://www.advancedcustomfields.com/changelog/
[1]: https://plugins.trac.wordpress.org/changeset?new=3164480%40a...
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#66I just cancelled my ACF subscription as it's up for renewal in 30 days. I'll wait and see how the dust settles.
My advice would be to make plans to move away from WordPress entirely. While I think that the “supply chain attack” is hyperbolic, if technically true, it’s indicative of an organization that cares about winning more than ensuring any form of stability whatsoever to their users and clients. Beware.
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#67So, ACF injected notices into everyone's dashboards to push their own legal agenda. It’s a move that reeks of self-interest more than community benefit. While everyone’s ready to grab their pitchforks at Matt, this actually sounds somewhat reasonable. Still, given its impact, this could easily be seen as a breach of trust. Definitely a move that's going to stir the pot.
PS: isn’t WooCommerce doing the exact same?
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#68The appropriate twist here would be to have WPEngine find a trusted third party (one or more), start a foundation together and successfully fork wordpress.
I think Matt would be quite happy with that. His issue is WP Engine not contributing to WordPress. If they decide to maintain a fork and infrastructure, they won't be freeloading anymore. Edit: That attracted a lot of downvotes. I was giving my option in response to the parent comment. In my option Automattic would be happy if they forked it.
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#69The appropriate twist here would be to have WPEngine find a trusted third party (one or more), start a foundation together and successfully fork wordpress.
Re: WordPress.org's latest move involves taking control of a WP Engine plugin
#70Earlier quoted context omitted.
They also have the worst social media team I have ever seen: https://x.com/WordPress/status/1845121130207535524
Who is she, though?
2. It takes one click to find out that she's the "founder of http://Client-Portal.io, a WP plugin for freelancers to use with their clients to keep track of all the deliverables in a centralized portal"