Authentication

Guide tag · 10 matching pages

Wordpress Alert: XML-RPC login abuse

Repeated authentication attempts arrive through XML-RPC on a site that exposes it. Attackers may test credentials through a second login surface.

Wordpress Alert: Weak password-reset tokens

A custom reset flow uses predictable, reusable, or long-lived tokens. Someone who obtains or guesses a token may reset another person's password.

Wordpress Alert: Two-factor authentication bypass in plugins

A third-party login route accepts a password without enforcing the site's second factor. A stolen password may become sufficient for account access.

Wordpress Alert: Stolen administrator session cookies

An active admin session is reused from another browser or location. The attacker can act as the administrator until the session is revoked.

Wordpress Alert: Session fixation

A session identifier survives the transition from signed-out to signed-in state. A person who knows the identifier may inherit the authenticated session.

Wordpress Alert: Password spraying against WordPress logins

One or a few common passwords are tried across many accounts. A weak account may be taken over without a large attack volume per user.

Wordpress Alert: Password-reset link disclosure

Reset URLs appear in logs, analytics, or unintended messages. Anyone with a valid link may take over the account before it expires.

Wordpress Alert: Application-password exposure

A WordPress application password appears in logs, backups, or a public repository. An external client may gain API access with that credential.

Wordpress Alert: Administrator credential stuffing

Many login attempts reuse passwords stolen from other services. A reused administrator password may give an attacker dashboard access.

Wordpress Alert: Account enumeration through login responses

Login or reset screens reveal whether an email address has an account. Attackers can build a target list for password attacks.