Over 100,000 websites are now infected with a very bad malware. In December 2014, the internet was attacked and a website soaksoak.ru was thrust into the news. The media immediately blamed WordPress as an insecure web platform… fortunately they are wrong!

WordPress is a community supported content management system millions of businesses use every day. When managed properly, WordPress is typically one of the safest platforms available. So, what happened?

The massive attack on websites running WordPress occurred because a slider plugin had vulnerabilities that the hackers exploited. They used the bug in the plugin to deposit malware on the website and inject itself into the web pages that were being served from the website. Now, this seems like something someone should have fixed, and fixed fast! Well, this bug was fixed… in February of 2014. So, how did this attack happen? How can something fixed 10 months earlier cause so much trouble?

WordPress plugins can update simply by clicking on the update link in the Plugins section. The problem is most people don’t think about their website from a maintenance point of view. They get busy running their business and suddenly they are significantly out of date on the software that runs their website.

Another problem, occasionally plugins will fail when they update. Sometimes in the update process, sometimes they change significantly and stop working the way you intended. In these cases it goes beyond a simple click of a link. Usually it requires some attention, but not to the programmer level. I have seen some plugins require a significant effort to recover, but usually well respected plugin authors are careful to make sure they are backward compatible.

