Hacker News new | ask | show | jobs
by usaphp 610 days ago
> replaced it with another plugin that broke people's websites

What makes you think it broke someone’s website? AFAIK they just patched the security issue that wp engine team couldn’t patch because they were locked out from pushing to repo?

2 comments

Firstly, the security patch was already published by the ACF team, and that wasn't the code that was pushed. This was a package takeover, slug, reviews, users, everything:

https://www.advancedcustomfields.com/blog/acf-plugin-no-long...

People woke up to their website being updated to “Secure Custom Fields”, an alternative (or a fork) that's not fully compatible. Here's one such report from HN:

https://news.ycombinator.com/item?id=41830709

They turned off all pro features
What Wordpress did is insane, but let’s not spread misinformation. There were no pro features in the free plugin to turn off, they removed advertising for the pro version.