• Something Burger 🍔@jlai.lu
    link
    fedilink
    English
    arrow-up
    20
    ·
    edit-2
    9 months ago

    Theme Forest and Envato marketplaces

    Also known as “the places where themes and plugins go when they are so shitty even WordPress.org doesn’t want them”. Never use anything that comes from these two sites.

  • wagesj45@kbin.social
    link
    fedilink
    arrow-up
    15
    arrow-down
    2
    ·
    9 months ago

    FYI, Publii is really good. It supports importing existing WordPress blogs and has a familiar interface. Great for those that don’t need built in comments and can use something like Cactus (if you like Matrix).

  • AutoTL;DR@lemmings.worldB
    link
    fedilink
    English
    arrow-up
    12
    arrow-down
    2
    ·
    9 months ago

    This is the best summary I could come up with:


    Thousands of sites running the WordPress content management system have been hacked by a prolific threat actor that exploited a recently patched vulnerability in a widely used plugin.

    The vulnerable plugin, known as tagDiv Composer, is a mandatory requirement for using two WordPress themes: Newspaper and Newsmag.

    Tracked as CVE-2023-3169, the vulnerability is what’s known as a cross-site scripting (XSS) flaw that allows hackers to inject malicious code into webpages.

    According to a post authored by security researcher Denis Sinegubko, threat actors are exploiting the vulnerability to inject web scripts that redirect visitors to various scam sites.

    The Balada Injector malware campaign performed a series of attacks targeting both the vulnerability in the tagDiv Composer plugin and blog administrators of already infected sites.

    Balada Injector hackers always aim for persistent control over compromised sites by uploading backdoors, adding malicious plugins, and creating rogue blog administrators.


    The original article contains 675 words, the summary contains 145 words. Saved 79%. I’m a bot and I’m open source!

  • AutoTL;DR@lemmings.worldB
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    6
    ·
    9 months ago

    This is the best summary I could come up with:


    Thousands of sites running the WordPress content management system have been hacked by a prolific threat actor that exploited a recently patched vulnerability in a widely used plugin.

    The vulnerable plugin, known as tagDiv Composer, is a mandatory requirement for using two WordPress themes: Newspaper and Newsmag.

    Tracked as CVE-2023-3169, the vulnerability is what’s known as a cross-site scripting (XSS) flaw that allows hackers to inject malicious code into webpages.

    According to a post authored by security researcher Denis Sinegubko, threat actors are exploiting the vulnerability to inject web scripts that redirect visitors to various scam sites.

    The Balada Injector malware campaign performed a series of attacks targeting both the vulnerability in the tagDiv Composer plugin and blog administrators of already infected sites.

    Balada Injector hackers always aim for persistent control over compromised sites by uploading backdoors, adding malicious plugins, and creating rogue blog administrators.


    The original article contains 675 words, the summary contains 145 words. Saved 79%. I’m a bot and I’m open source!