Wordpress Alert: Unauthorized user creation
A registration or import action creates accounts without the intended authorization. Attackers may create access paths or hidden administrators.
Guide tag · 10 matching pages
A registration or import action creates accounts without the intended authorization. Attackers may create access paths or hidden administrators.
A theme-management endpoint accepts a user without installation rights. Attacker-controlled theme code could be installed if other safeguards fail.
A low-privilege request updates site options or plugin configuration. Security controls, destinations, or site behavior may be changed.
A settings or profile request changes a user's capabilities unexpectedly. An attacker may gain more access or remove a defender's access.
A nonadministrator can activate installed code through a plugin or API flaw. New functionality may run with broad site privileges.
A subscriber can change their role or call a privileged plugin action. A basic account may become a site administrator.
A route or plugin reveals a post marked private to an unauthorized visitor. Restricted content becomes publicly accessible.
Changing a record ID exposes another user's booking, form entry, or file. Private information crosses account boundaries.
Unpublished drafts appear in a public response or cached page. Embargoed or incomplete material can leak.
A contributor gains an editor-only action through a plugin or custom route. The user may publish or alter content beyond their assigned role.