TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

WordPress: The Drama Continues

12 pointsby eamann7 months ago

2 comments

FireBeyond7 months ago
&gt; Were they right to do so? It&#x27;s complicated, but likely yes.<p>Going to disagree, there.<p>What did turning off some of the commercial features of the plugin have to do with the security fix?<p>WPE had already created a fix for the security issue. It was just being artificially being prevented from being deployed.<p>They didn&#x27;t just <i>fork</i> ACF into SCF. They forked it, then took over all of ACF&#x27;s reputation, rating, and are arguably committing trademark infringement in order to do so, none of which was needed for the security fix.<p>&gt; The WordPress.org team<p>Matt says himself &quot;I am WordPress.org. It&#x27;s not a part of the Foundation&quot; (but you&#x27;d be forgiven for thinking so, given that the website resides on the Foundations AS network...<p>As for the security fix itself:<p>It&#x27;s not much of one. It hides some POST variables or doesn&#x27;t populate them, but they&#x27;re still present in the REQUEST supervariable. It&#x27;s relatively pointless as a security fix because if there -was- an exploit for it, the exploit would still work with a simple &quot;s&#x2F;_POST&#x2F;_REQUEST&#x2F;g&quot;.<p>It also seems entirely likely that Matt directed engineers at Automattic to find something, anything, that could plausibly called a security hole so that he could artificially catalyze this situation into existence.
markx27 months ago
<a href="https:&#x2F;&#x2F;x.com&#x2F;deviorobert&#x2F;status&#x2F;1845843078189306185" rel="nofollow">https:&#x2F;&#x2F;x.com&#x2F;deviorobert&#x2F;status&#x2F;1845843078189306185</a><p>So far we&#x27;ve seen access to the following blocked by Matt via <a href="http:&#x2F;&#x2F;wordpress.org" rel="nofollow">http:&#x2F;&#x2F;wordpress.org</a><p>Advanced Custom Fieleds - @wp_acf<p>Nitropack - @getnitropack<p>Genesis Blocks - @studiopress<p>Better Search Replace - @dliciousbrains<p>PHP Compatibility Checker - @wpengine<p>WP Migrate Lite - @dliciousbrains<p>Frost theme - @bgardner
评论 #41839749 未加载