Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: New WordPress Security Changes Could Shift the Game for Hackers
Newsletter
Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: New WordPress Security Changes Could Shift the Game for Hackers
Newsletter
Search
  • Latest Stories
  • Security & Tech
    • Security
    • Vulnerabilities
    • Dark Web
    • Technology
    • Privacy
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
© MRS Media Company. Hackerdose LLC. All Rights Reserved.

Security » New WordPress Security Changes Could Shift the Game for Hackers

SecurityVulnerabilities

New WordPress Security Changes Could Shift the Game for Hackers

WordPress introduces mandatory two-factor authentication and SVN passwords to protect plugins and themes from future attacks.

Marco Rizal
Last updated: September 6, 2024 9:15 am
By Marco Rizal - Editor, Journalist 3 Min Read
Share
New WordPress Security Changes Could Shift the Game for Hacker
SHARE

WordPress has announced major security changes for its vast ecosystem of plugins and themes, which will be effective starting October 1, 2024.

These changes are in response to a series of attacks that targeted vulnerabilities in plugin developer accounts, potentially affecting millions of sites.

The new security measures are intended to strengthen protection at the source, ensuring that themes and plugins remain secure and reliable.

Every day, hackers took advantage of a flaw in WordPress's security system by using compromised passwords from previous breaches.

These attackers gained access to developer accounts with commit access, which enabled them to inject malicious code into plugins.

Once inside, they could compromise multiple WordPress sites by changing the code at the source level.

This demonstrates an obvious weakness in WordPress's security infrastructure, as developer accounts and plugin code access were not adequately protected.

To address this, WordPress is implementing a dual-layered security system that separates developer credentials from code access, preventing this type of attack from occurring again.

WordPress introduces two key security features to protect its plugins and themes:

Mandatory Two-factor authentication (2FA)

Beginning October 1, 2024, all plugin and theme developers must use two-factor authentication.

WordPress has already begun prompting users to enable 2FA as an extra layer of security for their accounts.

This plays a major part in preventing unauthorized access to developer accounts.

SVN Passwords

WordPress is also implementing Subversion (Subversion) passwords. These passwords provide a separate layer of security for developers with code commit access.

This means that even if an attacker gains access to a developer's main account, they will not have direct access to the plugin or theme code.

According to WordPress, SVN passwords work similarly to application-specific passwords, allowing developers to revoke access without changing their main WordPress.org credentials.

Developers can generate their SVN password from their WordPress.org profile.

Many people are relieved that these long-awaited changes are finally occurring. “Ouch, finally” one user commented, expressing frustration that this level of security was not implemented sooner.

However, some users remain doubtful, particularly given the system's limitations.

Due to technical limitations, 2FA cannot be applied directly to existing code repositories, so WordPress relies on SVN passwords instead.

These new security changes will also help to prevent ongoing malware campaigns such as the Balada Injector, which has been infecting WordPress sites since 2017.

According to security firm Sucuri, this campaign infected over one million websites by exploiting themes and plugin vulnerabilities.

Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newsletter

Receive the latest news and stories straight to your inbox.

Latest stories

Bitcoin Holds at $85K as Global Trade Tensions and Fed Speculation Unfold

April 15, 2025

Michael Saylor Doubles Down on Bitcoin (BTC) with $285M Investment Amid Global Uncertainty

April 14, 2025

Mantra Faces Crisis After OM Token Crashes 90% in a Day

April 14, 2025

Solana (SOL) on the Verge of a Breakout: Could $300 Be the Next Target?

April 14, 2025

You might also like

Norton Antivirus Jumps on Avasts Engine

One Less Scanner? Norton Antivirus Jumps on Avast’s Engine

Moonton Hacked

Hackers Leak Mobile Legends Source Code and Employee Data in Massive Breach

Global Police Operation Seizes 257 Million From Online Scammers

Global Police Operation Seizes $257 Million From Online Scammers

Hackers Are Buying Big YouTube Channels to Infect You with Malware

Hackers Are Buying Big YouTube Channels to Infect You with Malware

Newsletter

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site

Quick Links

  • Contact Us
  • Search
  • Malware
  • Downloads

Company

  • About Us
  • Terms and Conditions
  • Cookies Policy
  • Privacy Policy
Advertise with us

Socials

Follow Us

© 2025 | HackerDose Media Company – All Rights Reserved

Welcome Back!

Sign in to your account

Lost your password?