this post was submitted on 23 Jul 2026
97 points (97.1% liked)

Selfhosted

60951 readers
866 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

7.0.2 got released on Friday. Exploits are already happening. People reporting hacks

you are viewing a single comment's thread
view the rest of the comments
[–] ThanksObama@sh.itjust.works 24 points 4 days ago (4 children)

Correction: WordPress IS a critical vulnerability.

[–] 9point6@lemmy.world 16 points 4 days ago (1 children)
[–] chronicledmonocle@lemmy.world 6 points 3 days ago

JFC I thought you were exaggerating.

[–] SreudianFlip@sh.itjust.works 5 points 4 days ago

Anyone who hosts websites can check the logs and see the bots hammering away at wp/admin primarily, even if you are not running any WordPress. Low hanging meat? Fresh fruit?

[–] ctenidium@lemmy.world 1 points 3 days ago

Elementor makes it worse though.

[–] Marthirial@lemmy.world -2 points 4 days ago (4 children)

I have developed and hosted over 760 WP sites since 2006 and have never been hacked. Ever.

Mediocre craftspeople blame their tools.

[–] kungen@feddit.nu 12 points 4 days ago

I've driven a poorly designed car without many safety features for years, and I've never flown through the windshield, ever.

[–] loo@lemmy.world 7 points 4 days ago

Glad you got lucky. But a tool having one critical vulnerability after another has nothing to do with mediocre craftsmanship and blaming admins for getting hacked after updating their software is nothing but disrespectful and condescending

[–] LunarLoony@lemmy.sdf.org 5 points 3 days ago

How do you know?

[–] genzboomer@lemmy.zip 5 points 3 days ago

Professionals are never cocky. Cocky comes back to bite.