Wordpress Alert: Cross-site request forgery against settings
A signed-in administrator visits an external page that triggers a settings change. Configuration may change without the administrator intending it.
Guide category · 101 matching pages
A signed-in administrator visits an external page that triggers a settings change. Configuration may change without the administrator intending it.
Multiple sites share writable files or database credentials. Compromise of one site may affect another.
A low-privilege account can create or modify coupons. An attacker may issue discounts that the store never approved.
An affected WordPress version remains unpatched after the July 2026 security release. The documented flaw can let an attacker influence a database query under the advisory's conditions.
A contributor gains an editor-only action through a plugin or custom route. The user may publish or alter content beyond their assigned role.
A form plugin stores uploaded attachments at guessable public URLs. Private submissions may be readable by anyone with the URL.
An update arrives from an untrusted or compromised distribution channel. Malicious code may be installed as if it were a routine update.
A backup option is passed unsafely to a system command. The server may execute unintended commands.
A third-party page frames an admin screen and tricks a user into clicking it. A legitimate session may carry out an unintended action.
A checkout extension accepts files without suitable type or authorization checks. Customer-supplied files may become a code or data exposure route.
An extension trusts a client-submitted total instead of recalculating server-side. A buyer may be charged less than the actual order value.
A cache stores personalized or restricted output as a public response. One visitor may receive another user's content.
A booking link or token appears in a public response. Someone else may view or manage a reservation.
A booking plugin accepts a delete action from an unverified caller. Reservations may disappear or be canceled maliciously.
A restoration action accepts a caller without administrative rights. Site files and database contents may be replaced.
An importer unpacks an archive whose entries target paths outside its destination. Files elsewhere on the server may be overwritten.
A download handler accepts a path or ID outside the caller's allowed files. Private uploads or configuration files may be disclosed.
A cleanup or media handler deletes a path supplied by an unauthorized user. Site files or backups may be removed.
A WordPress application password appears in logs, backups, or a public repository. An external client may gain API access with that credential.
Many login attempts reuse passwords stolen from other services. A reused administrator password may give an attacker dashboard access.