Millions of WordPress sites just got hacked... again
Fireship
0:00 Eight months ago, some galaxyrained
0:02 hacker quietly penetrated the back door
0:04 of more than 30 WordPress plugins, and
0:06 no one noticed until now.
0:08 Somehow, this massive collection of different
0:10 WordPress plugins for silly UI updates
0:13 was instantly turned into malware with a
0:15 crazy supply chain attack.
0:16 That means one minute your countdown timer ultimate
0:19 plugin is converting sales on your
0:21 website, then the next minute it becomes
0:22 a remote control demon on your server
0:24 that steals all your data and leaks
0:26 photos of your wife's boyfriend to the
0:28 Kiwi Farms.
0:28 WordPress remains the most
0:30 popular website builder in the world,
0:32 but many people have argued that
0:33 WordPress's plug-in architecture is
0:35 fundamentally insecure and a brand new
0:38 slot fork has emerged to replace it.
0:39 In today's video, we'll find out how the
0:41 latest brutal exploit occurred and take
0:43 a look at this new project from
0:44 Cloudflare that hopes to terminate
0:46 WordPress from the timeline.
0:48 It is April 16th, 2026, and you're watching the code
0:51 report.
0:51 I actually love WordPress and
0:53 have built many failed side projects
0:54 with it, but the WordPress ecosystem has
0:56 experienced a wild couple of years.
0:58 Its founder, Matt Mullenweg, spurred out on
1:01 private equity last year because the
1:02 Silver Lake owned WP Engine was drinking
1:05 his milkshake by making money hosting
1:07 WordPress.
1:08 So, naturally, he demanded
1:09 that they pay him 8% of their revenue
1:11 for using his logo.
1:12 Now, as you all
1:13 know, I'm a huge fan of private equity
1:14 because they make every product better,
1:16 like Hooters, for example.
1:18 But WP Engine refused to pay the king as royalty.
1:20 that made Mullenweg spur out even harder and
1:22 he said a bunch of stuff that eventually
1:24 led to WP Engine filing a defamation
1:26 lawsuit against him.
1:27 They're still fighting each other in court to this day
1:29 and the lore goes way deeper.
1:31 But the bigger problem for WordPress is that
1:33 it's been experiencing a wave of new
1:35 vulnerabilities and 96% of those are a
1:37 direct result of its plug-in system.
1:39 The core problem is that a WordPress plug-in
1:41 is basically just a PHP script that
1:43 plugs straight into your site and starts
1:45 running with full privileges.
1:47 There's no sandbox or isolation.
1:48 It can touch your
1:49 database, your files, and your private
1:51 parts.
1:51 And when you install a plugin,
1:53 you're basically just hoping a stranger
1:54 knows how to handle every edge case,
1:56 exploit, and bad input perfectly.
1:58 What's crazy, though, is that this most recent
2:00 attack on 31 WordPress plugins was
2:03 actually not the result of bad code.
2:05 It's not your fault.
2:06 It was something far scarier.
2:08 In this case, the attacker didn't exploit a
2:10 vulnerability.
2:11 Instead, they legitimately acquired and took control
2:13 of a portfolio of plugins by simply
2:16 purchasing them for money from the
2:17 original developer on Flippa in a deal
2:20 with the sales price estimated to be in
2:21 the mid6 figures.
2:22 After the original developer was bought out, the new buyer
2:25 had control of the code and they
2:27 inserted a back door about 8 months ago
2:29 and it's just been sitting there dormant
2:30 in production waiting for the right
2:32 moment.
2:32 Then when the moment was right,
2:34 the malicious logic activated which
2:36 reached out to a remote server, pulled
2:38 down additional payloads and in some
2:39 cases modified core files like
2:42 wpconfig.php which includes sensitive data like your
2:45 database connection and security keys.
2:47 And apparently the command and control
2:49 domain was resolved through an Ethereum
2:51 smart contract.
2:52 So once the exploit
2:53 became known, the attacker could quickly
2:55 update the smart contract to point to a
2:57 new domain at any time.
2:58 That's pretty clever.
2:59 But the core issue here is that
3:01 everything was delivered through a
3:02 normal plug-in update from a trusted
3:04 source.
3:04 And so it bypassed the usual
3:06 suspicion of a normal fishing attack.
3:08 And now WordPress did step in and remove
3:10 the plugins.
3:11 But damage was already done
3:12 inside the system.
3:13 It turning what looked like routine maintenance into a
3:15 full-blown supply chain compromise.
3:17 Luckily though, if you're considering
3:18 using WordPress today, Cloudflare
3:20 recently created a new project called
3:22 Mdash, which takes all that old crappy
3:24 PHP code and turns it into something
3:26 even crappier, AI written JavaScript
3:29 code.
3:29 This project actually doesn't use
3:31 any original WordPress code and is MIT
3:33 licensed, but it's designed to be fully
3:35 compatible with the original WordPress
3:37 APIs.
3:38 And under the hood, it's based on
3:39 the awesome Astro project for its
3:41 content management system.
3:43 What makes this project special though is that it
3:45 doesn't let plugins run wild with full
3:47 access.
3:48 Mdash locks each plugin down in
3:49 its own sandbox with a dynamic worker.
3:52 The framework itself doesn't hand over
3:54 your data directly.
3:55 Instead, the plug-in only gets access to specific
3:58 capabilities through bindings and only
4:00 if it explicitly asks for them in the
4:01 manifest.
4:02 It's kind of like telling the
4:03 plugin, "No, no, don't touch me there.
4:05 This is my no square." Pretty cool, but
4:08 will mdash actually kill WordPress once
4:10 and for all?
4:10 The answer is probably not.
4:12 and definitely not anytime soon.
4:14 But the craziest thing to me is how quickly
4:16 developers can roll out complete
4:18 replacements for frameworks that have
4:19 been around forever.
4:20 And that's made possible by modern AI coding tools like
4:23 Warp, the sponsor of today's video.
4:25 If you're viaxing with Claude Code, Codeex,
4:28 Gemini CLI, and Open Code at the same
4:30 time, but keep losing track of all your
4:32 agents, you need to check out Warp's new
4:34 universal agent support, which turns
4:36 your terminal into an agent command
4:38 center.
4:38 Vertical tabs let you group your
4:40 agent sessions together and quickly see
4:42 useful metadata like get branch, work
4:44 tree, and pull request status, which
4:46 means your terminal finally has object
4:48 permanence.
4:49 And the tab configs let you
4:50 save your ideal setup and reopen it
4:52 instantly in the future.
4:54 The best part though is that you can get notifications
4:56 from your coding agents in Warp and on
4:58 your desktop whenever they need
4:59 attention instead of checking on them
5:01 every 30 seconds like a helicopter
5:03 parent.
5:03 So, if you already have an agent
5:05 you like or you want to try running
5:06 multiple agents at once, I'd highly
5:08 recommend checking out Warp for free at
5:10 the link below.
5:11 But this has been the
5:11 Code Report.
5:12 Thanks for watching and I
5:13 will see you in the next one.