- Feb 11, 2015
- 2,492
- 765
- First Name
- Alex
Definitely, there's no doubt about it. It's totally vulnerable.Some/many of my favorite sites and themes are WordPress. No question there. The dilemma is that WordPress is one of the most targeted platforms in the world for this reason. When an exploit is found by the wrong people, it can be devastating. The thing many don’t realize is that themes and plugins aren’t updated like the core is. Countless themeforest themes still contain a totally vulnerable version of timthumb that allows you to run arbitrary php code on the host server. It’s a wild world that I love/hate.
Custom development on top of it, like DI, is considerably safer, but users can still open vulnerabilities.
https://www.cvedetails.com/vulnerability-list/vendor_id-2337/product_id-4096/
https://wpvulndb.com/
I suppose some of the dedicated hosts out there, claim to stop attacks, but...