Wordpress Alert: Unprotected admin-post.php actions
A form handler trusts a submitted request without authorizing the user. A crafted request can change settings or content.
Guide tag · 10 matching pages
A form handler trusts a submitted request without authorizing the user. A crafted request can change settings or content.
A plugin AJAX action changes data without checking the caller's capability. An anonymous or low-privilege request may trigger the action.
A custom REST route returns private records or performs changes for a signed-out visitor. Data may leak or site state may change without an account.
An affected core version still exposes the vulnerable REST batch-route behavior. The documented route-confusion and SQL injection chain can lead to remote code execution.
A low-privilege account can invoke a REST action reserved for an editor or administrator. The account may gain publishing or administrative powers.
A logged-in user can retrieve or edit another user's resource by changing its identifier. Private records may be read or modified across accounts.
A REST update accepts fields the current user should not control, such as role or ownership. An ordinary edit can become a privilege or content-ownership change.
An affected version and the advisory's theme and server preconditions allow an unexpected local PHP file to be included. Under those conditions, unauthenticated code execution may follow.
A plugin registers a route that discloses internal data or actions more broadly than intended. Remote callers may reach functionality that was assumed to be private.
An affected WordPress version remains unpatched after the July 2026 security release. The documented flaw can let an attacker influence a database query under the advisory's conditions.