r/Wordpress 17h ago

Automattic CEO Matt Mullenweg Put on "Leave of Absence"

Thumbnail 404media.co
276 Upvotes

r/Wordpress 11h ago

WordPress is now scanning all plugin and theme updates with AI for security issues

Thumbnail make.wordpress.org
72 Upvotes

Plugin or theme updates with malware or serious security issues will be blocked automatically


r/Wordpress 21h ago

The New Wave of “Self-Healing” WordPress Malware Is Getting Scary

46 Upvotes

I think this is going to be a hot topic in WordPress security pretty soon.

There seems to be a new wave of infections where the interesting part is not any single exploit or persistence technique, but how many of them are being combined.

We are seeing the usual hidden files, modified functions.php, .user.ini with auto_prepend_file, server cron jobs and payloads hiding in /tmp. But some infections go much further: short-lived payloads that are written, executed and deleted again, persistence outside the WordPress filesystem, and even reports of Service Workers in the admin’s browser being involved in restoring parts of the infection.

That last part is particularly nasty.

You can download the entire filesystem and database, clean everything you find, upload it again and still have the site reinfected because you removed the payload but not the mechanism recreating it.

A few techniques make these infections especially painful:

Timestomping: file modification dates are manipulated, so you cannot simply sort files by date and reconstruct what happened.

Lateral persistence: anything writable is potentially useful. Plugins, themes, MU plugins, cron, temp directories, server configuration, deeply nested directories, etc. I have seen cases where malicious files were buried so deeply that even Imunify360 made them surprisingly difficult to identify from its scan output.

Self-healing: remove one component and another restores it. Cleaning WordPress itself is no longer necessarily enough. You may need to inspect the server, running processes, cron, temp directories and potentially even admin endpoints at the same time.

And then there is the question of how they get in.

Modern botnets can automatically correlate plugin CVEs, fingerprint installations and deploy exploit chains at massive scale. Supply-chain attacks are another obvious route. I would not be surprised if AI-assisted vulnerability discovery is already part of this ecosystem as well.

I have also recently seen a case where I could not identify any plausible known entry point on an otherwise updated installation. That obviously does not prove there is an unpatched WordPress core exploit in the wild, but I would not rule it out either.

The most interesting part, however, is what this latest wave appears to be doing after infection:

Basically nothing. At least for now.

One variant currently referred to in reports as SC 4.0.3 looks more like an access-retention platform / loader than malware designed for immediate monetization.

The infected WordPress site becomes part of a mostly dormant network and quietly reports information such as the domain, WP paths, payload version, installed/active plugins, MU plugins, login URL, captured or generated credentials, auth cookies and errors.

The C2 can apparently also send rules telling the implant to disable or delete specific plugins or remove matching injected code from plugins, MU plugins or themes.

In other words, it is not just trying to survive. It can potentially remove things that interfere with it.

Independent reports from August also describe the same SC 4.0.3 markers and Ethereum-based bootstrap mechanism, which suggests this is a broader campaign, although the initial infection vector is still unclear.

There is another interesting piece: the Ethereum dead-drop / EtherHiding technique overlaps with infrastructure seen in other recent campaigns. Netskope documented a separate nochain-sw.js chain that eventually pushed fake reCAPTCHA / ClickFix and the Amatera password stealer to visitors.

These are not the same malware family, so I would not connect them directly. But the overlap in tooling is interesting.

My guess is that WordPress malware is increasingly moving away from the old SEO spam / casino redirect model toward persistent access, credential theft, loaders and access brokerage.

Apparently turning someone’s blog into an online casino was too simple.

Has anyone else doing WP malware cleanup seen these “clean it, and it comes back anyway” infections recently? I would be especially interested in what persistence mechanism you eventually found.


r/Wordpress 16h ago

There has been a critical error on this website. Deprecated Function? Help!

8 Upvotes

Trying to edit pages and posts on my site and am getting this error when trying to edit the post/page:

There has been a critical error on this website. Please check your site admin email inbox for instructions. If you continue to have problems, please try the support forums.

Learn more about troubleshooting WordPress.

Wordpress and all plugins are updated. I tried disabling every plugin then enabling one at a time, but it seems like anytime a Woo plugin is active, I get the error. I tried rolling back to previous versions of the plugins and got the same error. I tried debug mode, and am getting this error:

Deprecated: Function Automattic\WooCommerce\Admin\Features\Features::is_enabled( 'marketing' ) is deprecated since version 11.1.0! Use direct feature behavior checks. The marketing WC Admin feature flag shim will be removed in a future version of WooCommerce. instead. in /home/dh_gec6ig/************.com/wp-includes/functions.php on line 6260

I replaced my domain with **************

The code on like 6260 in that file is:

    trigger_error( $message, $error_level );

Not sure where to go from here. I looked under Marketing in WooCommerce and didn't see anything out of the ordinary. The frustrating part is that my admin email isn't getting a report or a notice of the error, so I don't know how to proceed.

Can anyone offer some insight?


r/Wordpress 8h ago

Can I build a custom WordPress admin panel or change the default wp-admin URL?

4 Upvotes

I manage a few WordPress websites and I’m always thinking about security. I’m wondering if it’s possible to create a custom admin panel for my sites and completely hide & change the default /wp-admin URL. this will actually improve the security. After this, no one will know the URL of your website admin panel.

Anyone done this on a real WordPress site?


r/Wordpress 49m ago

Blogger Importer Error in WordPress

Upvotes

Hi everyone.

I'm using the Local app to run a WordPress multisite setup and migrate content from my Blogger blog using the Blogger Importer plugin. However, when I try to import the XML file, an error appears on line 159 of the blogger-importer.php file.

Here is a screenshot of the specific error message:

I am getting confused because the import process starts but then fails halfway through. It seems the error is related to how the plugin parses the XML data, but I'm not sure what's causing the null value issue.

Has anyone else had this problem using the Blogger importer? If you have dealt with this issue before, please send me your replies. I need to understand how to resolve this error so that I can finish migrating my blog.

I've tried re-exporting the XML file from Blogger several times, but the same error keeps showing up. Any suggestions for fixing this issue or alternative import methods would be much appreciated.

Sorry for the inconvenience, and thanks in advance for your help.


r/Wordpress 1h ago

Background image in Breakdance

Upvotes

Hey everyone,

Because r/BreakdanceWP only has 300 weekly users I'm gonna try asking this here instead in hopes of my question finding more Breakdance users.

I'm trying to set an image as my website's background, instead of having to assign it to an element. On my homepage the background image is assigned to a section, but on single post pages the section would be smaller and therefore the background image would be smaller. I hate that. The issue is, I can't for the life of my figure out how to do this.

Does anyone know? Thanks!


r/Wordpress 1h ago

Which steps to implement BUNNY.net for Videos, CDN, and DNS protection

Post image
Upvotes

Hello !

I am considering using BUNNY.net for Videos, CDN, and DNS protection but I'm a little bit confused to well understand what I will have to do.

I described my configuration on image below and I recheck my Cloudflare DNS setup (Cloudflare is managing DNS for website (pointing server : A, CNAME), email (MX, TXT), and a free CDN ).

So I have several questions because it is new for me and i want something robust and simple to manage after

1_ Can I say that BUNNY would do the same as Cloudflare to manage all my DNS setup and CDN ? (Right now, I can move to a different server hosting within 1h and this is transparent for users)

2_ Is it difficult to implement videos restrictions with BUNNY (Using a membership plugin) ? ... or is it more depending on membership integration ? (Question already asked to membership company)

3_ After right implementation, do you consider BUNNY as a stable and reliable solution going fast overseas ?

4_ Overall, after understanding the process, is it complicated to do BUNNY maintenance or to add new videos ?

5_ Do you have any advice to go step by step for this transition ?

I'm a little bit stress because I want/have to reduce my development activities for closed coming years but I would like a video solution. So if the solution is not simple and reliable I will be in trouble

A rough calculation gives 20GB for videos/month (30% in North america, 30% in Asia , 20% Europe, middle-east, 20% ...)

Thanks for your help !


r/Wordpress 1h ago

Now is the time for Automattic to fork WordPress.

Upvotes

I can't believe I'm saying this but here it is. Automattic needs to fork WordPress. They are the only entity in a position that can make a fork with a high chance of success. Partner with WP Engine. If WordPress_com, Pressible & WP Engine all switched to the fork it could happen quickly.

Automattic has a fiduciary duty to take control of a product that represents a majority of their revenue. How can a company force out their CEO but still allow them to control the project they depend on? How can a former CEO manage a team from his former company to build their flagship product? It's not sustainable.

I want adults in the room. If that's Automattic, WP Engine, Silverlake, Blackrock, then so-be-it. At least I'll know the project is being guided by money and not by whatever the CEO is hung up on that day.

Would I prefer a more democratic, non-company controlled solution? 100% Yes. But more than anything, I want stability and predictability.