Wordpress Alert: Writable theme or plugin editor abuse
A compromised administrator account edits executable site files from the dashboard. Malicious code can persist in a theme or plugin.
Guide tag · 10 matching pages
A compromised administrator account edits executable site files from the dashboard. Malicious code can persist in a theme or plugin.
A public form accepts a file type or location it should reject. The uploaded file may expose users or, in some configurations, execute server code.
A plugin includes code from a URL or untrusted location. Attacker-controlled code may run if the runtime and plugin permit it.
A database dump sits under a web-accessible directory. Visitors may download user and site data.
A theme selects a PHP template from untrusted input. A readable file outside the expected theme path may be included.
A migration package remains publicly downloadable after a move. It may contain database data and configuration secrets.
An upload accepts a file based only on its name or claimed content type. A script may be stored where it can be executed or served to visitors.
An importer unpacks an archive whose entries target paths outside its destination. Files elsewhere on the server may be overwritten.
A download handler accepts a path or ID outside the caller's allowed files. Private uploads or configuration files may be disclosed.
A cleanup or media handler deletes a path supplied by an unauthorized user. Site files or backups may be removed.