Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica)
Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica)
Posted Dec 11, 2014 2:54 UTC (Thu) by Baylink (guest, #755)In reply to: Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica) by raven667
Parent article: Four-year-old comment security bug affects 86 percent of WordPress sites (Ars Technica)
Certainly, but I believe you've misunderstood the assertion.
It is not that websites shouldn't *be* code.
It's that they shouldn't *run* code provided to them through their public user interfaces (probably "whether authenticated or not").
