|
|
|
|
|
by patio11
5165 days ago
|
|
Welcome to WordPress! + Marvel at the efficiency where anonymous subscribers are stored in the same database table as all-powerful system admins, which makes it much easier to upgrade anonymous Internet commenters to admins using local privilege escalation. + Enjoy at least five different ways to execute arbitrary code against the server from the admin console. For added fun, they're secured independently from each other! + Stop wasting time with fine-grained permissions models: all plugins/themes get unrestricted read/write access to the database and arbitrary code execution by default. + Experiencing a shortage of qualified engineers? No problem! We've lowered barriers to contribution so much that a significant portion of the community output has been made by people who know just enough PHP to eval($_GET["something"]). You'll find them in our semi-curated plugin/themes lists, sorted by star rating, with easy one-click access for admins to install on your server. (I actually like Wordpress, but certainly not for its security record.) |
|
I agree with your comment, though. Wordpress has poor coding practices built into the core (arguably like the language it's written in).