Skip to main content
Ahosting Logo
  • Hosting
    • WordPress Hosting
      Fast, secure hosting for WordPress sites
    • Web Hosting
      Reliable, affordable hosting for sites
    • FFMpeg Hosting
      Fast hosting for FFmpeg projects
    • Reseller Hosting
      Start hosting biz with white-label plans
    • VPS Hosting
      Scalable VPS with full control & power
    • Dedicated Server
      High-power servers for max security
    • WooCommerce Hosting
      Fast hosting for WooCommerce shops
  • Domain
    • Register a Domain
      Secure your domain name in minutes
    • Domain Transfer
      Move domains to Ahosting with ease
    • Premium SSL Certificate
      Enterprise SSL to build customer trust
  • Support
    • Submit A Ticket
      Expert 24/7 help from our support team
    • Abuse Report
      Report abuse to keep network safe
    • Knowledge Base
      Quick answers via step-by-step guides
  • Company
    • Blog
      Expert articles to power your online growth
    • Compare Hosts
      Side-by-side comparison
    • Datacenter
      Secure, high tech datacenter for hosting
    • About Us
      Learn about our mission, values & team
    • Contact Us
      Contact sales for plans, pricing & advice
    • Sitemap
      Find info fast with our clear site map
My Account
Ahosting Logo
  • Hosting
    • Web Hosting
    • WordPress Hosting
    • FFMpeg Hosting
    • Reseller Hosting
    • VPS Hosting
    • Dedicated Server
    • WooCommerce Hosting
  • Domain
    • Register a Domain
    • Domain Transfer
    • Premium SSL Certificate
  • Support
    • Knowledge Base
    • Abuse Report
    • Submit A Ticket
  • Company
    • About Us
    • Contact Us
    • Blog
    • Sitemap
    • Datacenter
  • Legal
    • Privacy Policy
    • Terms of Service
    • Acceptable Use Policy
    • Service Legal Agreement
    • Resource Abuse Policy
My Account

AHosting Blog Home

CMS-Targeted Attacks Are Only Going To Get More Frequent: Here’s How To Protect Yourself

CMS Targeted Attacks

Matt Chrust

Director of Business Development, AHosting Matt has led business development at AHosting since the company’s founding in 2002. He writes about WordPress hosting infrastructure, server performance, and the evolving requirements of WordPress sites at scale.

Last Updated

Home » Security » CMS-Targeted Attacks Are Only Going To Get More Frequent: Here’s How To Protect Yourself

Recently, Finnish security researcher Joukou Pynnonen revealed a security flaw in Yoast’s WordPress SEO plugin which allowed hackers to take over the administrator account of any CMS on which the plugin was installed. One of the most popular SEO tools on the web; Yoast’s plugin has been downloaded nearly seven million times – meaning there’s a staggering number of WordPress sites impacted by the vulnerability. Unfortunately, this story is nothing new.

It seems like every week, there’s some new crisis that content management systems have to deal with. There always seems to be some new vulnerability, new attack vector, or exploit that allows hackers to seize control of a site (or simply access a ton of sensitive information). More often than not, these security flaws are plugin-based; the result of poor coding or an oversight on the part of the developer.

If you think these vulnerabilities are popping up more and more frequently, you’re not imagining things. They are, and you shouldn’t be surprised. Content management systems run nearly 40% of the world’s websites, so it’s only natural that they’d become frequent targets – and that’s without even accounting for the fact that, thanks to their relatively open architecture, they’ve more points of attack than any other platform on the web.

That isn’t to say they’re inherently insecure, mind you. WordPress core, for example, is one of the most secure website creation tools in the world – provided, of course, you take the necessary precautions. That’s what we’re here to talk about today – what are those precautions?

In light of the fact that content management systems are being targeted with increasing – and alarming – frequency, how can you keep yourself safe?

  • Only Download Plugins From Reputable Developers: This one is huge – and probably one of the most valuable pieces of advice you’ll ever hear. Remember CryptoPHP? That was one of the worst pieces of malware to hit WordPress in years…but in order to become infected with it, you had to have downloaded a compromised plugin. I’d wager most of the sites that suffered from the vulnerability were using pirated addons or themes.
  • Pay Attention To The News: Preparedness is incredibly important – which is why you need to keep an ear to the ground as far as security is concerned. My advice is to set up a few Google alerts related to your CMS, and check them every day. That way, you’ll know ASAP when one of your plugins is vulnerable – and you can take whatever steps necessary to protect your site.
  • Patch Regularly: This should be obvious, but it needs to be said all the same – keep your site up to date. Whenever there’s a new security patch or hotfix released, install it.
  • Create Regular Backups: Sometimes, your site’s going to end up getting hit no matter what you do. Having some sort of scheduled backup system means that you can restore any data lost as a result of a compromise.
  • Make Sure Your Account Security Is Up To Snuff: One of the biggest vulnerabilities in your WordPress installation could well be your account. Having a username like ‘admin’ or a password like ‘default’ is basically asking for your site to get hacked – especially with brute force attacks on the rise. In addition to strengthening your passwords, you might consider using two-factor authentication along with some form of encryption.

There’s a reason we seem to hear about a new CMS vulnerability or attack vector every single week. Content Management systems are on the fast-track to becoming one of the most frequently-targeted mediums for cyber-criminals. It’s never been more important that you keep your stuff secure – no matter what platform you happen to be running.

If you aren’t regularly patching out vulnerabilities, taking proactive steps to manage your security, and keeping your passwords and accounts strong, then you’ve only yourself to blame if your installation ends up getting compromised.

Related posts:

More WordPress Plugin VulnerabilitiesMore WordPress Plugin Vulnerabilities Have Surfaced – Here’s What You Need To Know MODX StrengthsThe Five Greatest Strengths Of MODX Important To See To WordPress SecurityWhy It’s Now More Important Than Ever To See To Security On Your WordPress Blog Security WordPress InstallationThe All-Inclusive Guide To Securing Your WordPress Installation
«What IS A Content Delivery Network, Exactly?
Why It’s Now More Important Than Ever To See To Security On Your WordPress Blog»

Categories

  • CMS
  • Concrete5
  • Drupal
  • FFmpeg / Video Hosting
  • How To
  • Joomla
  • MODX
  • News Releases
  • Security
  • SEO
  • Uncategorized
  • Video Content
  • Web Hosting News
  • WooCommerce
  • WordPress

Lets Connect!

  • X
  • Facebook
  • LinkedIn
  • Instagram
  • YouTube
  • Pinterest
Ahosting Logo

Hosting

  • WordPress Hosting
  • Web Hosting
  • FFMpeg Hosting
  • WooCommerce Hosting
  • Reseller Hosting
  • VPS Hosting
  • Dedicated Server

Domain

  • Register a Domain
  • Domain Transfer
  • Premium SSL Certificate

Support

  • Knowledge Base
  • Abuse Report
  • Submit A Ticket

Company

  • About Us
  • Datacenter
  • Contact Us
  • Blog
  • Sitemap

Legal

  • Privacy Policy
  • Terms of Service
  • Acceptable Use Policy
  • Service Legal Agreement
  • Resource Abuse Policy
  • Hosting +
    • WordPress Hosting
    • Web Hosting
    • FFMpeg Hosting
    • Woocommerce Hosting
    • Reseller Hosting
    • VPS Hosting
    • Dedicated Server
  • Domain +
    • Register a Domain
    • Domain Transfer
    • Premium SSL Certificate
  • Support +
    • Knowledge Base
    • Abuse Report
    • Submit A Ticket
  • Company +
    • About Us
    • Datacenter
    • Contact Us
    • Blog
    • Sitemap
  • Legal +
    • Privacy Policy
    • Terms of Service
    • Acceptable Use Policy
    • Service Legal Agreement
    • Resource Abuse Policy

Copyright © All Rights Reserved