WordPress

Guide category · 101 matching pages

Wordpress Alert: Subscriber-to-administrator privilege escalation

A subscriber can change their role or call a privileged plugin action. A basic account may become a site administrator.

Wordpress Alert: Stored cross-site scripting in shortcodes

Untrusted shortcode attributes become executable HTML or JavaScript. A page view can run attacker-controlled script.

Wordpress Alert: Stored cross-site scripting in profiles

A user profile field executes code in another user's browser. Viewing the profile may trigger unwanted actions or data theft.

Wordpress Alert: Stored cross-site scripting in comments

A comment carries script-capable content that runs when staff view it. The script can act in the staff member's browser and may expose session data.

Wordpress Alert: Stored cross-site scripting in block attributes

A custom block saves a value that later executes in the editor or public page. Editors or visitors can be affected each time the block renders.

Wordpress Alert: Stolen administrator session cookies

An active admin session is reused from another browser or location. The attacker can act as the administrator until the session is revoked.

Wordpress Alert: Staging-to-production credential reuse

A staging site's exposed password or token also works on production. Compromise of the test site may lead to production access.

Wordpress Alert: SQL injection in sorting parameters

A user-controlled sort field is inserted into a database query. The query structure may be altered if the field is not allowlisted.

Wordpress Alert: SQL injection in search filters

A plugin builds a database query from a search filter without safe parameterization. Attackers may read or change data under the vulnerable query's conditions.

Wordpress Alert: SQL injection in reporting dashboards

Report filters become part of an unsafe SQL query. Sensitive records may be exposed or reports altered.

Wordpress Alert: SQL injection in form plugins

A form lookup or submission filter is concatenated into SQL. Saved entries may be read or modified.

Wordpress Alert: SQL injection in booking plugins

A booking search or calendar parameter reaches an unsafe query. Reservation and customer data may be exposed.

Wordpress Alert: Spreadsheet formula injection in exported CSV files

A form or report export begins a cell with formula syntax. Opening the CSV in spreadsheet software may execute a formula.

Wordpress Alert: Session fixation

A session identifier survives the transition from signed-out to signed-in state. A person who knows the identifier may inherit the authenticated session.

Wordpress Alert: Server-side template injection

A theme or builder evaluates user-controlled text as a template. Template capabilities may disclose data or run unintended operations.

Wordpress Alert: Server-side request forgery in URL preview tools

A preview tool fetches an attacker-supplied URL from the server. The server may reach internal services or metadata endpoints.

Wordpress Alert: Server-side request forgery in import tools

An importer downloads content from an unrestricted address. Internal services may be reached through the WordPress host.

Wordpress Alert: REST batch-route confusion leading to code execution (CVE-2026-63030)

An affected core version still exposes the vulnerable REST batch-route behavior. The documented route-confusion and SQL injection chain can lead to remote code execution.

Wordpress Alert: REST API privilege escalation

A low-privilege account can invoke a REST action reserved for an editor or administrator. The account may gain publishing or administrative powers.

Wordpress Alert: REST API object authorization bypass

A logged-in user can retrieve or edit another user's resource by changing its identifier. Private records may be read or modified across accounts.