Core Security

Guide tag · 10 matching pages

Wordpress Alert: Unprotected admin-post.php actions

A form handler trusts a submitted request without authorizing the user. A crafted request can change settings or content.

Wordpress Alert: Unprotected admin-ajax.php actions

A plugin AJAX action changes data without checking the caller's capability. An anonymous or low-privilege request may trigger the action.

Wordpress Alert: Unauthenticated REST endpoint access

A custom REST route returns private records or performs changes for a signed-out visitor. Data may leak or site state may change without an account.

Wordpress Alert: REST batch-route confusion leading to code execution (CVE-2026-63030)

An affected core version still exposes the vulnerable REST batch-route behavior. The documented route-confusion and SQL injection chain can lead to remote code execution.

Wordpress Alert: REST API privilege escalation

A low-privilege account can invoke a REST action reserved for an editor or administrator. The account may gain publishing or administrative powers.

Wordpress Alert: REST API object authorization bypass

A logged-in user can retrieve or edit another user's resource by changing its identifier. Private records may be read or modified across accounts.

Wordpress Alert: REST API mass assignment

A REST update accepts fields the current user should not control, such as role or ownership. An ordinary edit can become a privilege or content-ownership change.

Wordpress Alert: Page-template local file inclusion (CVE-2026-87902)

An affected version and the advisory's theme and server preconditions allow an unexpected local PHP file to be included. Under those conditions, unauthenticated code execution may follow.

Wordpress Alert: Exposed custom REST routes

A plugin registers a route that discloses internal data or actions more broadly than intended. Remote callers may reach functionality that was assumed to be private.

Wordpress Alert: Core facilitated SQL injection (CVE-2026-60137)

An affected WordPress version remains unpatched after the July 2026 security release. The documented flaw can let an attacker influence a database query under the advisory's conditions.