100 WordPress Security Alerts
A numbered index of 100 WordPress security alerts with links to the individual guides.
Guide category · 101 matching pages
A numbered index of 100 WordPress security alerts with links to the individual guides.
Login or reset screens reveal whether an email address has an account. Attackers can build a target list for password attacks.
Many login attempts reuse passwords stolen from other services. A reused administrator password may give an attacker dashboard access.
A WordPress application password appears in logs, backups, or a public repository. An external client may gain API access with that credential.
A cleanup or media handler deletes a path supplied by an unauthorized user. Site files or backups may be removed.
A download handler accepts a path or ID outside the caller's allowed files. Private uploads or configuration files may be disclosed.
An importer unpacks an archive whose entries target paths outside its destination. Files elsewhere on the server may be overwritten.
A restoration action accepts a caller without administrative rights. Site files and database contents may be replaced.
A booking plugin accepts a delete action from an unverified caller. Reservations may disappear or be canceled maliciously.
A booking link or token appears in a public response. Someone else may view or manage a reservation.
A cache stores personalized or restricted output as a public response. One visitor may receive another user's content.
An extension trusts a client-submitted total instead of recalculating server-side. A buyer may be charged less than the actual order value.
A checkout extension accepts files without suitable type or authorization checks. Customer-supplied files may become a code or data exposure route.
A third-party page frames an admin screen and tricks a user into clicking it. A legitimate session may carry out an unintended action.
A backup option is passed unsafely to a system command. The server may execute unintended commands.
An update arrives from an untrusted or compromised distribution channel. Malicious code may be installed as if it were a routine update.
A form plugin stores uploaded attachments at guessable public URLs. Private submissions may be readable by anyone with the URL.
A contributor gains an editor-only action through a plugin or custom route. The user may publish or alter content beyond their assigned role.
An affected WordPress version remains unpatched after the July 2026 security release. The documented flaw can let an attacker influence a database query under the advisory's conditions.
A low-privilege account can create or modify coupons. An attacker may issue discounts that the store never approved.