Wordpress Ocean Extra Plugin hacked

needtraffic24

Regular Member
Joined
Feb 12, 2024
Messages
224
Reaction score
63
I came across an article that mentioned this plugin has affected more than 600,000 websites. If that's the case, why do people still choose to use WordPress, especially considering its vulnerability to hacking?
 
I came across an article that mentioned this plugin has affected more than 600,000 websites. If that's the case, why do people still choose to use WordPress, especially considering its vulnerability to hacking?

lazy. i would never use wordmess for a web site.
 
What platform would you suggest?

i write my own html code or i use a template. are you familiar with the 'panama papers' scandal that exposed tax cheats? reportedly that was the result of a hack into a wordpress site that used an unsecured plugin which allowed someine to access confidential info.
 
People uses wp as easy to maintain, no other easy tools like wp to create awesome website. But it is really sad that wp doesn't take action for these type of virus.
 
You know it's fine to link here right?

From my understanding Wordpress by itself is very secure.

Once you start adding in plugins that haven't been updated in 20 years.

That's when you get issues.
Ocean has been getting regularly updated.
 
Key part of the vulnerability: "authenticated attackers, with contributor-level access and above"

Unless they have a user login with contributor level access (eg. can write articles) they can't exploit anything.
 
I suspect that many WP bloggers fail to keep their plugins updated and also do not configure their blog's settings correctly. I once checked the html code on a business blog and it was configured to block search engines.

the business owner didn't know that their idiot webmaster had configured the blog in such a way that potential clients would never be able to find them with a search engine.
 
Last edited:
I want to suggest you scan your site for malware, and change all passwords.
 
If Ocean Extra was hacked, disable/remove the plugin, restore from a clean backup, run a malware scan (Wordfence/MaICare), update WP/plugins, reset all passwords & keys, and contact your host. I can post extra cleanup steps if you need them.
 
Back
Top