<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin&#x27;s ownership changes?]]></title><description><![CDATA[<p>This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin's ownership changes?</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://news.ycombinator.com/item?id=47755629" title="Someone bought 30 WordPress plugins and planted a backdoor in all of them | Hacker News">
<img src="https://news.ycombinator.com/y18.svg" class="card-img-top not-responsive" style="max-height:15rem" alt="Link Preview Image" />
</a>





<div class="card-body">
<h5 class="card-title">
<a href="https://news.ycombinator.com/item?id=47755629">
Someone bought 30 WordPress plugins and planted a backdoor in all of them | Hacker News
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://news.ycombinator.com/item?id=47755629" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://news.ycombinator.com/y18.svg" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(news.ycombinator.com)</span></p>
</a>
</div><p></p>]]></description><link>https://board.circlewithadot.net/topic/da0815c1-1f03-4ac5-bcc1-0e5b3ca2c6a1/this-discussion-atop-hackernews-right-now-about-how-someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them-has-me-wondering-is-there-a-plugin-that-blocks-plugins-from-being-automagically-updated-if-the-plugin-s-ownership-changes</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Apr 2026 08:31:20 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/da0815c1-1f03-4ac5-bcc1-0e5b3ca2c6a1.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 14 Apr 2026 12:44:08 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin&#x27;s ownership changes? on Tue, 14 Apr 2026 13:11:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> So How many plugins could a hacker backdoor, if a plugin could block backdoored plugins?</p>]]></description><link>https://board.circlewithadot.net/post/https://mastodon.social/users/kidko92/statuses/116403225458936940</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mastodon.social/users/kidko92/statuses/116403225458936940</guid><dc:creator><![CDATA[kidko92@mastodon.social]]></dc:creator><pubDate>Tue, 14 Apr 2026 13:11:03 GMT</pubDate></item><item><title><![CDATA[Reply to This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin&#x27;s ownership changes? on Tue, 14 Apr 2026 13:08:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> And is it for sale?</p>]]></description><link>https://board.circlewithadot.net/post/https://fosstodon.org/users/NeilShadrach/statuses/116403215561693870</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://fosstodon.org/users/NeilShadrach/statuses/116403215561693870</guid><dc:creator><![CDATA[neilshadrach@fosstodon.org]]></dc:creator><pubDate>Tue, 14 Apr 2026 13:08:32 GMT</pubDate></item><item><title><![CDATA[Reply to This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin&#x27;s ownership changes? on Tue, 14 Apr 2026 12:53:56 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> Plugin ownership is a slippery concept.<br />Many wordpress plugins are published by small companies that can be bought outright.</p>]]></description><link>https://board.circlewithadot.net/post/https://mas.to/users/mbpaz/statuses/116403158137059631</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://mas.to/users/mbpaz/statuses/116403158137059631</guid><dc:creator><![CDATA[mbpaz@mas.to]]></dc:creator><pubDate>Tue, 14 Apr 2026 12:53:56 GMT</pubDate></item><item><title><![CDATA[Reply to This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin&#x27;s ownership changes? on Tue, 14 Apr 2026 12:53:30 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/briankrebs%40infosec.exchange" aria-label="Profile: briankrebs@infosec.exchange">@<bdi>briankrebs@infosec.exchange</bdi></a> <a class="plugin-mentions-user plugin-mentions-a" href="/user/andrewnez%40mastodon.social" aria-label="Profile: andrewnez@mastodon.social">@<bdi>andrewnez@mastodon.social</bdi></a> would definitely know. He's the supply chain expert.</p>
]]></description><link>https://board.circlewithadot.net/post/https://toot.pouyan.net/objects/d4ab7f35-1f3d-4617-bc73-8655d6dd624b</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://toot.pouyan.net/objects/d4ab7f35-1f3d-4617-bc73-8655d6dd624b</guid><dc:creator><![CDATA[i@toot.pouyan.net]]></dc:creator><pubDate>Tue, 14 Apr 2026 12:53:30 GMT</pubDate></item><item><title><![CDATA[Reply to This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin&#x27;s ownership changes? on Tue, 14 Apr 2026 12:48:32 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> and who updates that one?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/noplasticshower/statuses/116403136889660852</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/noplasticshower/statuses/116403136889660852</guid><dc:creator><![CDATA[noplasticshower@infosec.exchange]]></dc:creator><pubDate>Tue, 14 Apr 2026 12:48:32 GMT</pubDate></item><item><title><![CDATA[Reply to This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin&#x27;s ownership changes? on Tue, 14 Apr 2026 12:48:30 GMT]]></title><description><![CDATA[<p><span><a href="/user/jackryder%40infosec.exchange">@<span>jackryder</span></a></span> <span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> This is NOT a new issue, which is probably why there is conversation.  People have a preset viewpoint.</p><p>I don't know how they are gonna solve that problem, but with the constant political shakeups at Wordpress, woof.  I'm just glad I got my last client off of WordPress.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116403136820441250</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116403136820441250</guid><dc:creator><![CDATA[sempf@infosec.exchange]]></dc:creator><pubDate>Tue, 14 Apr 2026 12:48:30 GMT</pubDate></item><item><title><![CDATA[Reply to This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin&#x27;s ownership changes? on Tue, 14 Apr 2026 12:48:03 GMT]]></title><description><![CDATA[<p><span><a href="/user/roses4cardinals%40hachyderm.io">@<span>Roses4Cardinals</span></a></span> I was being only partially facetious here. IMHO, this should be WordPress's job, whether or not you host a blog with them, seeing as they automatically update your plugins now whether you want them to or not.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/briankrebs/statuses/116403135019558084</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/briankrebs/statuses/116403135019558084</guid><dc:creator><![CDATA[briankrebs@infosec.exchange]]></dc:creator><pubDate>Tue, 14 Apr 2026 12:48:03 GMT</pubDate></item><item><title><![CDATA[Reply to This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin&#x27;s ownership changes? on Tue, 14 Apr 2026 12:47:49 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> But what if the plugin that blocks plugins from being automagically updated if the plugin's ownership changes' ownership changes?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/davep/statuses/116403134133463403</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/davep/statuses/116403134133463403</guid><dc:creator><![CDATA[davep@infosec.exchange]]></dc:creator><pubDate>Tue, 14 Apr 2026 12:47:49 GMT</pubDate></item><item><title><![CDATA[Reply to This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin&#x27;s ownership changes? on Tue, 14 Apr 2026 12:46:52 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> How much to buy hypothetical plugin that blocks plugins from updating?</p>]]></description><link>https://board.circlewithadot.net/post/https://hachyderm.io/ap/users/116081745495211516/statuses/116403130360461918</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://hachyderm.io/ap/users/116081745495211516/statuses/116403130360461918</guid><dc:creator><![CDATA[roses4cardinals@hachyderm.io]]></dc:creator><pubDate>Tue, 14 Apr 2026 12:46:52 GMT</pubDate></item><item><title><![CDATA[Reply to This discussion atop Hackernews right now about how someone bought 30 WordPress plugins and planted a backdoor in all of them has me wondering, is there a plugin that blocks plugins from being automagically updated if the plugin&#x27;s ownership changes? on Tue, 14 Apr 2026 12:46:05 GMT]]></title><description><![CDATA[<p><span><a href="/user/briankrebs%40infosec.exchange">@<span>briankrebs</span></a></span> There is <em>a lot</em> of conversation going on about this new issue.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116093572746253175/statuses/116403127275107749</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116093572746253175/statuses/116403127275107749</guid><dc:creator><![CDATA[jackryder@infosec.exchange]]></dc:creator><pubDate>Tue, 14 Apr 2026 12:46:05 GMT</pubDate></item></channel></rss>