File Security

Guide tag · 10 matching pages

Wordpress Alert: Writable theme or plugin editor abuse

A compromised administrator account edits executable site files from the dashboard. Malicious code can persist in a theme or plugin.

Wordpress Alert: Unauthenticated arbitrary file upload

A public form accepts a file type or location it should reject. The uploaded file may expose users or, in some configurations, execute server code.

Wordpress Alert: Remote file inclusion in plugins

A plugin includes code from a URL or untrusted location. Attacker-controlled code may run if the runtime and plugin permit it.

Wordpress Alert: Publicly accessible database backups

A database dump sits under a web-accessible directory. Visitors may download user and site data.

Wordpress Alert: Local file inclusion in themes

A theme selects a PHP template from untrusted input. A readable file outside the expected theme path may be included.

Wordpress Alert: Exposed migration archives

A migration package remains publicly downloadable after a move. It may contain database data and configuration secrets.

Wordpress Alert: Executable files disguised as images

An upload accepts a file based only on its name or claimed content type. A script may be stored where it can be executed or served to visitors.

Wordpress Alert: Archive extraction path traversal

An importer unpacks an archive whose entries target paths outside its destination. Files elsewhere on the server may be overwritten.

Wordpress Alert: Arbitrary file read through download endpoints

A download handler accepts a path or ID outside the caller's allowed files. Private uploads or configuration files may be disclosed.

Wordpress Alert: Arbitrary file deletion

A cleanup or media handler deletes a path supplied by an unauthorized user. Site files or backups may be removed.