WordPress

Guide category · 101 matching pages

100 WordPress Security Alerts

A numbered index of 100 WordPress security alerts with links to the individual guides.

Wordpress Alert: Account enumeration through login responses

Login or reset screens reveal whether an email address has an account. Attackers can build a target list for password attacks.

Wordpress Alert: Administrator credential stuffing

Many login attempts reuse passwords stolen from other services. A reused administrator password may give an attacker dashboard access.

Wordpress Alert: Application-password exposure

A WordPress application password appears in logs, backups, or a public repository. An external client may gain API access with that credential.

Wordpress Alert: Arbitrary file deletion

A cleanup or media handler deletes a path supplied by an unauthorized user. Site files or backups may be removed.

Wordpress Alert: Arbitrary file read through download endpoints

A download handler accepts a path or ID outside the caller's allowed files. Private uploads or configuration files may be disclosed.

Wordpress Alert: Archive extraction path traversal

An importer unpacks an archive whose entries target paths outside its destination. Files elsewhere on the server may be overwritten.

Wordpress Alert: Backup restoration without authorization

A restoration action accepts a caller without administrative rights. Site files and database contents may be replaced.

Wordpress Alert: Booking deletion without authorization

A booking plugin accepts a delete action from an unverified caller. Reservations may disappear or be canceled maliciously.

Wordpress Alert: Booking token disclosure

A booking link or token appears in a public response. Someone else may view or manage a reservation.

Wordpress Alert: Cache poisoning that exposes private pages

A cache stores personalized or restricted output as a public response. One visitor may receive another user's content.

Wordpress Alert: Cart total manipulation

An extension trusts a client-submitted total instead of recalculating server-side. A buyer may be charged less than the actual order value.

Wordpress Alert: Checkout-field upload vulnerabilities

A checkout extension accepts files without suitable type or authorization checks. Customer-supplied files may become a code or data exposure route.

Wordpress Alert: Clickjacking of administrative actions

A third-party page frames an admin screen and tricks a user into clicking it. A legitimate session may carry out an unintended action.

Wordpress Alert: Command injection in backup tools

A backup option is passed unsafely to a system command. The server may execute unintended commands.

Wordpress Alert: Compromised third-party plugin updates

An update arrives from an untrusted or compromised distribution channel. Malicious code may be installed as if it were a routine update.

Wordpress Alert: Contact-form attachment disclosure

A form plugin stores uploaded attachments at guessable public URLs. Private submissions may be readable by anyone with the URL.

Wordpress Alert: Contributor-to-editor privilege escalation

A contributor gains an editor-only action through a plugin or custom route. The user may publish or alter content beyond their assigned role.

Wordpress Alert: Core facilitated SQL injection (CVE-2026-60137)

An affected WordPress version remains unpatched after the July 2026 security release. The documented flaw can let an attacker influence a database query under the advisory's conditions.

Wordpress Alert: Coupon creation without authorization

A low-privilege account can create or modify coupons. An attacker may issue discounts that the store never approved.