6 ms·
Should say what plugin it is.
by giingyui 1y ago
Should say what plugin it is.
- Etheryte 1y agoIt's in the title? It's the official GravityForms plugin, supposedly version 2.9.13 fixes the issue, but the changelog [0] doesn't even mention the breach. [0] https://docs.gravityforms.com/gravityforms-change-log/ https://docs.gravityforms.com/gravityforms-change-log/
- giingyui 1y ago[dead]
- redrove 1y agoHonestly it still required a web search on my part to figure out it’s a WordPress plugin. That should be in the title.
- autoexec 1y agoAny time I read the words vulnerable and plugin I just assume WordPress is involved somehow. I'm convinced that the internet would be instantly more secure if the entire platform died off.
- d0mine 1y agoWordpress dominates internet outside megacorps. There are a lot of security issues but there is a lot of utility too.
- ChrisMarshallNY 1y agoIt would. It also would be a lot less useful. A lot of content is published through WordPress. I suspect an effective approach would be encouraging ways to make WP more secure, or publish a secure platform that can easily be transitioned from WP.
- swang 1y agoyou're not suppose to editorialize or change the title per HN rules.
- rectang 1y agoThere's a blog post about the incident: https://www.gravityforms.com/blog/security-incident-notice/ https://www.gravityforms.com/blog/security-incident-notice/