- Sep 10, 2010
- 11,805
- 26,657
Correct to a certain extent, but not totally. Wordpress has certain rules and regulations that you have to follow in order to upload your plugin to their directory. Your plugin is manually checked before you are given access to svn etc. So, it is safer than you think it is, but yes, there can still be exploits ( in 99% cases, it's a RFI vulnerability as I have been saying)..
You people mentioned almost everything. Good work! One thing to be added: for a hacker its always simplier to attack one of the plugins then WP itself. WP is backed up by a team of professionals, plugins are often someone's hobby. So don't use very exotic plugins.
AND MAKE BACKUPS!
D.