WordPress Is Still The KING!

Roger Marquez

Elite Member
Joined
Apr 17, 2017
Messages
5,126
Reaction score
7,822
cms-market-share-10k-websites-61070f7b493bd-sej.jpg

 
since it does provide the most and best of options, then its completely normal
 
as well as being super friendly and too many customizable options :p
I'm surprised blogger is still alive
 
Is the most hackble
It would be the same for anything with the biggest market slice. You don't get that achievement with low amounts of features, and the more features you have the more exploits exist. And of course, the more popular you are, the more people try and exploit you. An unfixable problem most likely
 
I don't know why people cry and talk so much, but i legit find WP the best over all other alternatives
 
Because it's most widely used. Right?
Almost.
Don't also that most attacks succeed because people are too lazy to update theirs tools. Of course, 0days exist & could be use but if you are careful, you back up regularly your code, content and install snapshots on your server, you are safe in 95% of the cases.
 
but the most succesful companies usually dont do everything of that type, they have personal scripts
 
It's modular, it scales and there's tons of plugins.

It's not more hackable - it's just that people don't lockdown their sites properly or run plugins that are nulled or poorly coded, so it serves as an attack vector.

That goes for many CMS, but Wordpress is so popular that it's more profitable to focus on finding ways to hack it. Just note 99% of the hacks are targeting plugins, and not the base CMS.

The people who poop on Wordpress usually code in another language and are unhappy at how popular it is.
 
It should be obvious, there is much more customizations using word press and more freedom especially if you want to make a very intuitive system.
 
It's also because most of vuln are easy to exploit with some tools - Metasploit or WPScan - and this tools are built in by default in Kali (formely BackTrack).
Even if you are not a cador, you can use WPScan. To summarize, you don't have to understand how infosec runs or how WordPress runs to use WPScan. Just check on YouTube "WPScan+Kali" to see how simple is.
 
That's not true. If you keep the core, plugins and your theme up-to-date and they are not cracked, you should be completely fine.
There are some exploits on wordpress that are not even public even if you have all your plugins/themes updated.
 
There are some exploits on wordpress that are not even public even if you have all your plugins/themes updated.
For the *latest* core version of WordPress? Even if that's true, how do you reckon it happening with WordFence and ModSecurity + CSF on the server-level? Please hit me up and I'll gladly let you try if you have such an exploit :)
 
Back
Top