Posted in

How Recent Cyberattacks are Forcing Many to Reevaluate their WordPress Plugin Collection

Cyberthreats and bad actors have a tendency to go after the most popular platforms because the attack surface increases with the number of people using it. Since WordPress is one of the most widely deployed systems for managing individual websites, it’s also become among those that are most sought out by crackers and other digital criminals. Considering the sheer complexity of the platform, those who’d like to take control of a remote system may find it surprisingly easy to do so.

Basic underlying WordPress deployments are generally secure, especially if administrators are diligent about installing all of the relevant updates. However, the nearly infinite combination of different plugins and add-ons that are in use makes it difficult to predict the exact chances of any given attack. Some of the older ones are vulnerable to SQL injection attacks and the platform as a whole is heavily reliant on dated PHP-based technologies.

While this news may sound somewhat grim, there are fortunately many ways that individual WordPress users can shore up their operations and lock down their sites to at least some degree. In most cases, this process is going to involve auditing your plugins. While there is no clear cut way of doing so, chances are good that a bit of simple logic can go a long way toward ensuring that any given deployment is as safe as possible.

Figuring Out When Good WordPress Plugins Have Gone Bad

It’s important to keep in mind that the mere act of installing plugins isn’t necessarily a bad one, and in many cases it could be absolutely necessary. Website administrators need some way of extending WordPress beyond its most primitive structure and plugins satisfy that need. Without them, designers would only be able to create simplified blog structures that provide no way to communicate with users outside of a comments section at the bottom of the page. Quite a few people who deploy WordPress technology are relying on it as part of an eCommerce venture, which means they need to install shopping cart plugins as well as those designed to take inventory and process shipping information.

On the other hand, a reliance on too many plugins has been the bane of many designers. Each additional piece of code brought into a project could drag heretofore unknown issues into it, and many of these are loaded with additional dependencies that few people take the time to audit manually. Even if they did know precisely how each plugin worked, it’s almost impossible to calculate the odds of any specific exploit coming to fruition with this much code attached to a single program.

That’s gotten many in the industry steamed, especially because they have little recourse when it comes time to single out the specific cause of any given security problem. Some people are of the opinion that every single piece of software in use has at least some form of undiscovered zero-day threat attached to it, so it makes sense that an increased amount of code would also translate into an increased number of problems.

To make things more confusing for security researchers, there are more than 50,000 plugins offered in the official store and even more that private users could purchase commercially. Some have tried to discover purported security problems by offering prizes of upwards of €1,500 in the hopes that someone might come across a potential exploit that wasn’t mapped before. However, it’s likely that many risks can never be discovered in sanitary lab conditions merely because you’d need to have multiple plugins installed in a specific way that only ever happens in the wild.

Though these various issues have all conspired together to make life very difficult for security researchers, many zero-day exploits do eventually get patched. When they do, system administrators get a rare opportunity to clean up their own operations. It’s difficult to tell just how many take advantage of it, however. Any monitoring program would naturally come with its own potential issues, so few people have even endeavored to collect any accurate measurements.

Deciding When the Right Time is to Install Updates on WordPress

Update compliance is somewhat uneven, with many users waiting to install them for quite some time after they’re released. At times, needed security updates could harm important functionality so the fact that some people are adverse to installing them is quite understandable. Nevertheless, this represents one of the biggest threats to security on the platform and it’s therefore of paramount importance that more people in the industry pay close attention to update schedules. For that matter, it’s perhaps equally important that developers are open about their schedules so users can make adjustments accordingly. They may actually be more likely to install updates if they’re given the opportunity to do so on their own terms.

According to official statistics, around 100,000 sites run something called the WordPress Download Manager, which could put them at risk for a situation where it’s possible for low-privilege contributors to retrieve the contents of their PHP files. All such a user would have to create a single extra download and they’d be able to gain access. While installing a recent hotfix would patch this issue out of existence, it seems that many are reluctant to do so. Though this position may be at least somewhat understandable, it’s also potentially quite unwise considering that sophisticated monster-in-the-middle attacks can seize control of un-patched systems.

Perhaps the easiest way for system administrators to proceed is to simply use a much smaller collection of plugins than they currently do. Concerned site operators are encouraged to remove any plugins or remnants that they’re not actively working with. Each of these represents both a potential attack vector as well as a performance problem. The WordPress platform has to periodically enumerate all of the code attached to it, after all, and having additional instruction sets in there can start to cause conflicts.

Individuals who are building a site from the ground up will want to only install the most essential WordPress plugins for their use case. By putting together a collection of core plugins in the beginning, these users can resist the urge to install unnecessary ones later on. This should also make it easier to maintain over the long-term.

Cutting Back on the Number of Plugins You Use

With more than 50,000 plugins currently available for download, it’s extremely easy to fall into the trap of installing far too many. Many new web developers will start to bring over any plugin that seems to solve a perceived issue simply so they don’t have to deal with it. When they do, they might be bringing along code that’s incredibly difficult to audit.

While it’s certainly true that a large number of plugins are open source, few organizations have the sheer amount of personnel needed to go through every plugin they install. Even if they could, it’s doubtful that each potential outcome could be predicted. If someone could figure out a way of calculating the odds of any specific security issue coming about because of a combination of different pieces of software running side-by-side, then they’d probably win some kind of award.

At first, it can be pretty difficult to decide which plugins you want to get rid of. There’s a good chance that you’ve come to rely on most of the ones that you have installed. Take a good look at the list and you’ll probably see a few that have very similar feature sets. If that’s the case, then keep the one that serves your needs better and uninstall the other.

Plugins that haven’t received any sort of updates in a long period of time should be removed as well. While an allowance could be made for mature ones, unsupported plugins are likely to become unsafe over time. After you’ve pared down the number of plugins you have, chances are fairly good that you will have already dramatically improved your security position.

From there, you’ll also be in a better position to keep your installation neat and tidy.

Maintaining WordPress Systems in a Safe & Logical Manner

It seems somewhat obvious that those who use fewer slices of code are going to run into less difficulties, but this isn’t always an option. Sophisticated eCommerce and news aggregation sites need equally elaborate tools to get the job done. That being said, all site operators are encouraged to audit the tools that they’re currently using and see if they can get rid of anything.

Of equal importance is the underlying platform upon which individual WordPress sites are based. Even the most secure WordPress installation can become a target if the actual software and hardware infrastructure deployment is problematic as was seen in the various SolarWinds attacks. Operators are encouraged to work with hosts that use hardened platforms to deploy their software in the first place.

It can be exhausting, but they should also keep an eye on any recent developments. This doesn’t have to be as tiresome as it sounds, though. One study claimed that over 36 percent of all unique security problems discovered with WordPress sites last year were related to cross-site scripting exploits. By keeping a close eye on the infosec community, site administrators would have been able to catch these problems early on and stopped them before they became bigger issues. In a best case scenario, they could have installed a single update and been done with it.

By taking the time to do these things now, everyone can save a substantial amount of time later by not having to unravel issues that would have otherwise become entrenched in the technologies they rely on.

 

My primary focus is a fusion of technology, small business, and marketing. I’m an editor, writer, marketing consultant and guest author at several authority websites. In love with startups, latest tech trends and helping others get their ideas off the ground.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.