{"id":21454,"date":"2023-09-16T11:14:06","date_gmt":"2023-09-16T09:14:06","guid":{"rendered":"https:\/\/wpbeveiligen.nl\/?p=21454"},"modified":"2023-07-13T11:16:06","modified_gmt":"2023-07-13T09:16:06","slug":"hacking-the-text-editor-in-wordpress","status":"publish","type":"post","link":"https:\/\/wpbeveiligen.nl\/en\/hacking-the-text-editor-in-wordpress\/","title":{"rendered":"Hacking the text editor in WordPress"},"content":{"rendered":"

Hackers, click away. We’re not going to teach you how to hack WordPress!!<\/em><\/p>\n

Now that the hackers are gone, let’s continue with this article.<\/p>\n

The text editor hack<\/h2>\n

A common hack, you see nothing on the page and nothing in your editor.
\nUntil you click on the Text editor tab! Suddenly, there’s ugly code.<\/p>\n

Don’t be mistaken, this code is carefully chosen and does more to your website than you want to know.<\/p>\n

    \n
  1. That piece of ugly text\/code can make visitors see an iFrame<\/a>.
    \nThat’s an entirely different website that appears on top of your website.<\/em><\/li>\n
  2. That piece of ugly code can redirect visitors to another website.
    \nFor example, the hacker’s webshop.<\/em><\/li>\n
  3. That piece of ugly code generates descriptions in Google.
    \nThink “Buy ….. at www…..nl”<\/li>\n
  4. That piece of ugly code can turn any word into a link.
    \nLinks to a criminal’s webshop.<\/em><\/li>\n
  5. And much more!<\/li>\n<\/ol>\n

    With JavaScript on your website or on various pages, almost anything is possible!<\/p>\n

    You don’t want that code in your pages. Especially not secretly, as you may only notice it months later.<\/p>\n

    How can you find out if you have that ugly code in your website?<\/h2>\n

    Simply check the text editor. (Or database table: wp_post)<\/p>\n

    How can you prevent that ugly code from getting into your website?<\/h2>\n

    Unfortunately, that code is very easy to inject through a database query. Through an XSS<\/a>, a vulnerability in a plugin<\/a>, and 30 other ways.<\/p>\n

    So,<\/strong><\/p>\n

      \n
    1. Regularly update your website<\/li>\n
    2. Don’t use too many plugins<\/a><\/li>\n
    3. Use strong passwords<\/a><\/li>\n
    4. Install an Antivirus plugin for WordPress<\/a> that prevents injections, hacks, and hackers (Configure it properly!!<\/em>)<\/li>\n
    5. Keep only the theme you’re using on the server<\/li>\n
    6. And lastly, but the first thing you should do now: back up<\/a> your website!<\/li>\n<\/ol>\n

      If you’re having trouble, hire us<\/a>. It will save you a lot of headache and time, and you’ll know that your website is in professional hands.<\/p>\n","protected":false},"excerpt":{"rendered":"

      Hackers, click away. We’re not going to teach you how to hack WordPress!! Now that the hackers are gone, let’s continue with this article. The text editor hack A common hack, you see nothing on the page and nothing in your editor. Until you click on the Text editor tab! Suddenly, there’s ugly code. Don’t […]<\/p>\n","protected":false},"author":4,"featured_media":9657,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[186],"tags":[],"_links":{"self":[{"href":"https:\/\/wpbeveiligen.nl\/wp-json\/wp\/v2\/posts\/21454"}],"collection":[{"href":"https:\/\/wpbeveiligen.nl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wpbeveiligen.nl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wpbeveiligen.nl\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/wpbeveiligen.nl\/wp-json\/wp\/v2\/comments?post=21454"}],"version-history":[{"count":0,"href":"https:\/\/wpbeveiligen.nl\/wp-json\/wp\/v2\/posts\/21454\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wpbeveiligen.nl\/wp-json\/wp\/v2\/media\/9657"}],"wp:attachment":[{"href":"https:\/\/wpbeveiligen.nl\/wp-json\/wp\/v2\/media?parent=21454"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wpbeveiligen.nl\/wp-json\/wp\/v2\/categories?post=21454"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wpbeveiligen.nl\/wp-json\/wp\/v2\/tags?post=21454"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}