Wordpress Alert: Malicious redirects through open-redirect flaws
A site link forwards visitors to an attacker-chosen destination. The trusted domain can be used in phishing links.
Guide category · 101 matching pages
A site link forwards visitors to an attacker-chosen destination. The trusted domain can be used in phishing links.
A pirated package contains hidden code or a modified updater. It may create a backdoor or steal data.
A theme selects a PHP template from untrusted input. A readable file outside the expected theme path may be included.
A course route exposes lessons to a user who has not enrolled. Paid or restricted learning material may leak.
Site files or directories are writable by more users or processes than needed. An attacker with limited access may alter code or content.
Changing a record ID exposes another user's booking, form entry, or file. Private information crosses account boundaries.
A gift-card extension trusts balance changes from an unauthorized request. Store credit may be created or spent improperly.
A form endpoint exposes saved entries beyond the intended staff roles. Contact details or confidential messages may leak.
A copied configuration file is served as plain text from the web root. Database credentials and security keys may leak.
A migration package remains publicly downloadable after a move. It may contain database data and configuration secrets.
A plugin registers a route that discloses internal data or actions more broadly than intended. Remote callers may reach functionality that was assumed to be private.
A plugin renders a secret in a public page, response, or log. Third parties may call connected services or APIs.
An upload accepts a file based only on its name or claimed content type. A script may be stored where it can be executed or served to visitors.
An event plugin lists attendee details to the wrong users. Names and contact information may be disclosed.
A contact form accepts newline or header syntax in email fields. Messages may gain unintended recipients or headers.
Unpublished drafts appear in a public response or cached page. Embargoed or incomplete material can leak.
Builder JavaScript inserts untrusted URL or content data into the page unsafely. The browser executes script even if the server response is static.
A database tool is reachable from the public internet without adequate controls. A second administrative surface may put site data at risk.
An API or plugin returns customer records to an unauthorized caller. Personal and purchase information may be exposed.
An external page induces an authenticated administrator to change an account. Users or roles may be created, deleted, or changed.