• Design
  • SEO
  • Portfolio
  • Why Choose Us
  • Blog
  • Contact
  • Facebook
  • Google+
Precise Online ManagementPrecise Online Management
  • Design
  • SEO
  • Portfolio
  • Why Choose Us
  • Blog
  • Contact
  • Facebook
  • Google+

Popular WordPress plugin website defaced by an upset former employee

WPML defaced

Popular WordPress plugin website defaced by an upset former employee

January 21, 2019 News, Security

News Courtesy of ZDNet.com:

A very popular WordPress plugin was hacked over the weekend after a hacker defaced its website and sent a mass message to all its customers revealing the existence of supposed unpatched security holes. In a follow-up mass email, the plugin’s developers blamed the hack on a former employee, who also defaced their website.

The plugin in question is WPML (or WP MultiLingual), the most popular WordPress plugin for translating and serving WordPress sites in multiple languages.

According to its website, WPML has over 600,000 paying customers and is one of the very few WordPress plugins that is so reputable that it doesn’t need to advertise itself with a free version on the official WordPress.org plugins repository.

– Read Source Article

Ryan’s Take

Just to be clear, the plugin itself wasn’t hacked. Rather this alleged bitter ex-employee left a backdoor to gain access to his former company’s website. While WPML was quick to notify their customers of the breach, the damage had already been done. Forced to rebuild the server, data that has been lost or comprised due to the hack has caused the company great frustration in time and money spent.

If indeed this attack was carried out by a former employee, it has to be one of the dumbest of all time. Jail time and fines are certain to follow for the perpetrator. I’m sure many of us have been unfairly treated by a former boss or two. However, that doesn’t excuse such behavior as to destroy property and harass or intimidate that company’s clients.

Reviewing the list of known vulnerabilities, it seems like all but one occurred in 2015. Reading from the notes, after being made aware of these vulnerabilities, WPML was quick to issue patches. The email/post created by the attacker claims to be a victim of the plugin’s vulnerability, however, no further information on the matter was given. Without any data to back up this claim, the “victim’s” story starts to fall apart.

Hopefully, this becomes a cautionary tale to companies that they need to really limit server access to trusted and essential employees. Personally, I’m hesitant giving any sort of privileges to my VPS to other administrators. If that becomes a problem, I’ll advise that they take their website and host it elsewhere. There is just too much at stake to even leave the possibility of an attack or hack.

0 0 votes
Article Rating
Share
0

About Ryan Faucher

Owner-operator of Precise Online Management. I also manage Kettlebell Krusher, a website dedicated to all things kettlebell as well a blog for my weight loss progress.

Subscribe
Notify of
guest
guest
0 Comments
Inline Feedbacks
View all comments

Categories

  • News
  • Niche Dreams
  • Reviews
  • Security
  • SEO
  • Tips

Recent Posts

  • 9 Benefits of Social Media for Your Organization
  • Advantages of Having Marketing Research Samples
  • Link Building Services: How To Find A Trustworthy Provider
  • SAS Affiliate Review and Tips for Affiliate Marketers
  • Comparison Of The Best Link Indexing Service Features & Benefits

Archives

  • January 2022
  • January 2021
  • October 2020
  • September 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • September 2019
  • August 2019
  • July 2019
  • June 2019
  • May 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
Ready to get started? Pick and choose your website and / or SEO services Order Services

© 2025 · Precise Online Management, LLC.
This site is owned and operated by Ryan Faucher

  • Visit Us on Facebook
  • Visit Us On Google+
Prev Next
wpDiscuz
X
WEB DESIGN SPECIAL PRICING - Over 60% off design packages through Fiverr
See Details