WordPress Plugins from A to Z

WordPress Plugins from A to Z


Weathering The Storm

February 20, 2020

It's Episode 448 and I am Weathering The Storm while Working though the 2020 hack meltdown with a couple of plugins and some ClassicPress Options. It's all coming up on WordPress Plugins A-Z!
According to the Meuller Report your are listening to, “WP Plugins A to Z The Best ClassicPress/WordPress Podcast in the Universe ”
A Big Thank You to the No Agenda Show for their contributions of ideas and the occasional sound clip.
This is a value for value show and I look forward to everyone providing some value back.
Subscribed to the newsletter for additional information and get out there and hit everyone in the mouth, Spread the word about WP Plugins A to Z and catch it live every Thursday at noon on my YouTube Channel.
Producer Credits:
Show Art:
Angel Lemus of https://www.koadigital.com/
All the show notes can be found at: WPPluginsAtoZ.com
Johns Rant:
Its episode 447 and I am a little punchy and still a bit tired and I am still looking for more participation from you the producers this year as the sword of Damocles is still hanging over the show. Keep the feedback coming….. This is #8 of 52 episodes for 2020..
I am looking for guest hosts to appear on the show starting in March, if you would like to join me as a guest host please reach out to me at john@wppro.ca
Well I forgot what it was like to pull an all niter been a couple years since the last time I had to do that. It seems the Hack that I had tweeted out earlier this week hit one of my clients who has multiple sites and we had to deal with a full blown melt down. So far we have been dealing with 12 sites and wile this hack is insidious it also appears we have been dealing with a previous hack that was not yet fully utilized and started working at the same time. This all started late Monday night

Yes I feel there is a special place in hell for the hackers that create this kind of havock. It often boggles my mind in that with the skill set involved in creating these hacks if they where applied creativatly to something that would help the world they could make some good coing doing that.

It always seems like an arms race between those that are trying to stop the hackers and those that hack the events just keep getting more and more creative. Look for more information about this when I do my presentation Feb 25 live here also.
WordPress News and Info
Malicious attack ongoing
https://www.reddit.com/r/Wordpress/comments/f5fqze/malicious_attack_ongoing/
Bug in WordPress plugin can let hackers wipe up to 200,000 sites
https://www.zdnet.com/article/bug-in-wordpress-plugin-can-let-hackers-wipe-up-to-200000-sites/
Critical Issue In ThemeGrill Demo Importer Leads To Database Wipe and Auth Bypass
https://www.webarxsecurity.com/critical-issue-in-themegrill-demo-importer/
lesson once your done with a plugin deactivate and remove this does not provide full protection but is some help
well we are not alone on this one
Can a JS script block a whole server? If so, how can I possibly get rid of this attack?
https://stackoverflow.com/questions/60275015/can-a-js-script-block-a-whole-server-if-so-how-c...