Wordpress Alert: Subscriber-to-administrator privilege escalation
A subscriber can change their role or call a privileged plugin action. A basic account may become a site administrator.
Guide category · 101 matching pages
A subscriber can change their role or call a privileged plugin action. A basic account may become a site administrator.
Untrusted shortcode attributes become executable HTML or JavaScript. A page view can run attacker-controlled script.
A user profile field executes code in another user's browser. Viewing the profile may trigger unwanted actions or data theft.
A comment carries script-capable content that runs when staff view it. The script can act in the staff member's browser and may expose session data.
A custom block saves a value that later executes in the editor or public page. Editors or visitors can be affected each time the block renders.
An active admin session is reused from another browser or location. The attacker can act as the administrator until the session is revoked.
A staging site's exposed password or token also works on production. Compromise of the test site may lead to production access.
A user-controlled sort field is inserted into a database query. The query structure may be altered if the field is not allowlisted.
A plugin builds a database query from a search filter without safe parameterization. Attackers may read or change data under the vulnerable query's conditions.
Report filters become part of an unsafe SQL query. Sensitive records may be exposed or reports altered.
A form lookup or submission filter is concatenated into SQL. Saved entries may be read or modified.
A booking search or calendar parameter reaches an unsafe query. Reservation and customer data may be exposed.
A form or report export begins a cell with formula syntax. Opening the CSV in spreadsheet software may execute a formula.
A session identifier survives the transition from signed-out to signed-in state. A person who knows the identifier may inherit the authenticated session.
A theme or builder evaluates user-controlled text as a template. Template capabilities may disclose data or run unintended operations.
A preview tool fetches an attacker-supplied URL from the server. The server may reach internal services or metadata endpoints.
An importer downloads content from an unrestricted address. Internal services may be reached through the WordPress host.
An affected core version still exposes the vulnerable REST batch-route behavior. The documented route-confusion and SQL injection chain can lead to remote code execution.
A low-privilege account can invoke a REST action reserved for an editor or administrator. The account may gain publishing or administrative powers.
A logged-in user can retrieve or edit another user's resource by changing its identifier. Private records may be read or modified across accounts.