Access Control

Guide tag · 10 matching pages

Wordpress Alert: Unauthorized user creation

A registration or import action creates accounts without the intended authorization. Attackers may create access paths or hidden administrators.

Wordpress Alert: Unauthorized theme installation

A theme-management endpoint accepts a user without installation rights. Attacker-controlled theme code could be installed if other safeguards fail.

Wordpress Alert: Unauthorized settings changes

A low-privilege request updates site options or plugin configuration. Security controls, destinations, or site behavior may be changed.

Wordpress Alert: Unauthorized role changes

A settings or profile request changes a user's capabilities unexpectedly. An attacker may gain more access or remove a defender's access.

Wordpress Alert: Unauthorized plugin activation

A nonadministrator can activate installed code through a plugin or API flaw. New functionality may run with broad site privileges.

Wordpress Alert: Subscriber-to-administrator privilege escalation

A subscriber can change their role or call a privileged plugin action. A basic account may become a site administrator.

Wordpress Alert: Private post access bypass

A route or plugin reveals a post marked private to an unauthorized visitor. Restricted content becomes publicly accessible.

Wordpress Alert: Insecure direct object references in plugins

Changing a record ID exposes another user's booking, form entry, or file. Private information crosses account boundaries.

Wordpress Alert: Draft content disclosure

Unpublished drafts appear in a public response or cached page. Embargoed or incomplete material can leak.

Wordpress Alert: Contributor-to-editor privilege escalation

A contributor gains an editor-only action through a plugin or custom route. The user may publish or alter content beyond their assigned role.