Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack
Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack

Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack

Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack
Backdoor slipped into multiple WordPress plugins in ongoing supply-chain attack
You're asking for trouble if you're using such random plugins on production sites.
oh boy, the average wordpress site has like 30 plugins and the top bar is getting cluttered with so many plugin upsells that it fills the whole screen. There's a huge industry of people making wordpress sites who shouldn't.
It's quite frustrating to be asked as a dev to "fix" people's site as my usual response is "shut it off and redo it well".
It's really a shame because by now WordPress itself actually works quite well. Sure, it's fueled by unspeakably ugly spaghetti code. But at least it's unspeakably ugly spaghetti code that works and receives regular automatic updates.
And other than putting up a verification program I don't see what they could do to improve the plugin situation.
And this is why I hate the state of the whole hacking scene and that now nation states are also carrying out en masse attacks. Everyone should be free to make a site on Wordpress or whatever. If they can't, that's how we get everyone on like 3 corporate platforms like Facebook.
Funnily enough, I was hearing this from developers in the early 2010s when I was just starting my career (IT adjacent, but not a developer).