Skip to main content

Comments

2 comments

  • cPRex Jurassic Moderator

    Hey there!  First of all, sorry about the delay in approving this as I was out sick for a bit.

    I did speak with the team about this and we have a couple thoughts.  First, I think this article is written specifically to be a bit dramatic.  There's not a specific known attack you can perform with the mentioned weakness, even though it isn't best practice.  I would say this isn't different from any other tool that runs as root, whether or not this cPanel or WP Toolkit is involved or not.

    With that being said, the WP Toolkit team has case EXTWPTOOLK-9855 open to work on removing the need for this level of access for the tool, although is it a major rewrite and I don't have an EAT just yet.

     

    0
  • verdon

    Thanks cpRex. I appreciate the response!

    0

Please sign in to leave a comment.