Millions of WordPress sites just got hacked... again

Millions of WordPress sites just got hacked... again

Fireship

0:00 Eight months ago, some galaxyrained

0:02 hacker quietly penetrated the back door

0:04 of more than 30 WordPress plugins, and

0:06 no one noticed until now.

0:08 Somehow, this massive collection of different

0:10 WordPress plugins for silly UI updates

0:13 was instantly turned into malware with a

0:15 crazy supply chain attack.

0:16 That means one minute your countdown timer ultimate

0:19 plugin is converting sales on your

0:21 website, then the next minute it becomes

0:22 a remote control demon on your server

0:24 that steals all your data and leaks

0:26 photos of your wife's boyfriend to the

0:28 Kiwi Farms.

0:28 WordPress remains the most

0:30 popular website builder in the world,

0:32 but many people have argued that

0:33 WordPress's plug-in architecture is

0:35 fundamentally insecure and a brand new

0:38 slot fork has emerged to replace it.

0:39 In today's video, we'll find out how the

0:41 latest brutal exploit occurred and take

0:43 a look at this new project from

0:44 Cloudflare that hopes to terminate

0:46 WordPress from the timeline.

0:48 It is April 16th, 2026, and you're watching the code

0:51 report.

0:51 I actually love WordPress and

0:53 have built many failed side projects

0:54 with it, but the WordPress ecosystem has

0:56 experienced a wild couple of years.

0:58 Its founder, Matt Mullenweg, spurred out on

1:01 private equity last year because the

1:02 Silver Lake owned WP Engine was drinking

1:05 his milkshake by making money hosting

1:07 WordPress.

1:08 So, naturally, he demanded

1:09 that they pay him 8% of their revenue

1:11 for using his logo.

1:12 Now, as you all

1:13 know, I'm a huge fan of private equity

1:14 because they make every product better,

1:16 like Hooters, for example.

1:18 But WP Engine refused to pay the king as royalty.

1:20 that made Mullenweg spur out even harder and

1:22 he said a bunch of stuff that eventually

1:24 led to WP Engine filing a defamation

1:26 lawsuit against him.

1:27 They're still fighting each other in court to this day

1:29 and the lore goes way deeper.

1:31 But the bigger problem for WordPress is that

1:33 it's been experiencing a wave of new

1:35 vulnerabilities and 96% of those are a

1:37 direct result of its plug-in system.

1:39 The core problem is that a WordPress plug-in

1:41 is basically just a PHP script that

1:43 plugs straight into your site and starts

1:45 running with full privileges.

1:47 There's no sandbox or isolation.

1:48 It can touch your

1:49 database, your files, and your private

1:51 parts.

1:51 And when you install a plugin,

1:53 you're basically just hoping a stranger

1:54 knows how to handle every edge case,

1:56 exploit, and bad input perfectly.

1:58 What's crazy, though, is that this most recent

2:00 attack on 31 WordPress plugins was

2:03 actually not the result of bad code.

2:05 It's not your fault.

2:06 It was something far scarier.

2:08 In this case, the attacker didn't exploit a

2:10 vulnerability.

2:11 Instead, they legitimately acquired and took control

2:13 of a portfolio of plugins by simply

2:16 purchasing them for money from the

2:17 original developer on Flippa in a deal

2:20 with the sales price estimated to be in

2:21 the mid6 figures.

2:22 After the original developer was bought out, the new buyer

2:25 had control of the code and they

2:27 inserted a back door about 8 months ago

2:29 and it's just been sitting there dormant

2:30 in production waiting for the right

2:32 moment.

2:32 Then when the moment was right,

2:34 the malicious logic activated which

2:36 reached out to a remote server, pulled

2:38 down additional payloads and in some

2:39 cases modified core files like

2:42 wpconfig.php which includes sensitive data like your

2:45 database connection and security keys.

2:47 And apparently the command and control

2:49 domain was resolved through an Ethereum

2:51 smart contract.

2:52 So once the exploit

2:53 became known, the attacker could quickly

2:55 update the smart contract to point to a

2:57 new domain at any time.

2:58 That's pretty clever.

2:59 But the core issue here is that

3:01 everything was delivered through a

3:02 normal plug-in update from a trusted

3:04 source.

3:04 And so it bypassed the usual

3:06 suspicion of a normal fishing attack.

3:08 And now WordPress did step in and remove

3:10 the plugins.

3:11 But damage was already done

3:12 inside the system.

3:13 It turning what looked like routine maintenance into a

3:15 full-blown supply chain compromise.

3:17 Luckily though, if you're considering

3:18 using WordPress today, Cloudflare

3:20 recently created a new project called

3:22 Mdash, which takes all that old crappy

3:24 PHP code and turns it into something

3:26 even crappier, AI written JavaScript

3:29 code.

3:29 This project actually doesn't use

3:31 any original WordPress code and is MIT

3:33 licensed, but it's designed to be fully

3:35 compatible with the original WordPress

3:37 APIs.

3:38 And under the hood, it's based on

3:39 the awesome Astro project for its

3:41 content management system.

3:43 What makes this project special though is that it

3:45 doesn't let plugins run wild with full

3:47 access.

3:48 Mdash locks each plugin down in

3:49 its own sandbox with a dynamic worker.

3:52 The framework itself doesn't hand over

3:54 your data directly.

3:55 Instead, the plug-in only gets access to specific

3:58 capabilities through bindings and only

4:00 if it explicitly asks for them in the

4:01 manifest.

4:02 It's kind of like telling the

4:03 plugin, "No, no, don't touch me there.

4:05 This is my no square." Pretty cool, but

4:08 will mdash actually kill WordPress once

4:10 and for all?

4:10 The answer is probably not.

4:12 and definitely not anytime soon.

4:14 But the craziest thing to me is how quickly

4:16 developers can roll out complete

4:18 replacements for frameworks that have

4:19 been around forever.

4:20 And that's made possible by modern AI coding tools like

4:23 Warp, the sponsor of today's video.

4:25 If you're viaxing with Claude Code, Codeex,

4:28 Gemini CLI, and Open Code at the same

4:30 time, but keep losing track of all your

4:32 agents, you need to check out Warp's new

4:34 universal agent support, which turns

4:36 your terminal into an agent command

4:38 center.

4:38 Vertical tabs let you group your

4:40 agent sessions together and quickly see

4:42 useful metadata like get branch, work

4:44 tree, and pull request status, which

4:46 means your terminal finally has object

4:48 permanence.

4:49 And the tab configs let you

4:50 save your ideal setup and reopen it

4:52 instantly in the future.

4:54 The best part though is that you can get notifications

4:56 from your coding agents in Warp and on

4:58 your desktop whenever they need

4:59 attention instead of checking on them

5:01 every 30 seconds like a helicopter

5:03 parent.

5:03 So, if you already have an agent

5:05 you like or you want to try running

5:06 multiple agents at once, I'd highly

5:08 recommend checking out Warp for free at

5:10 the link below.

5:11 But this has been the

5:11 Code Report.

5:12 Thanks for watching and I

5:13 will see you in the next one.

Study with Looplines Download Captions Watch on YouTube