Wordpress Alert: Public .git directories
A deployed repository directory is web-accessible. Source code and sometimes secrets may be retrievable.
Guide tag · 10 matching pages
A deployed repository directory is web-accessible. Source code and sometimes secrets may be retrievable.
A debug or error log can be downloaded by visitors. Stack traces, tokens, or personal data may be exposed.
The web server executes scripts stored in uploads. An upload flaw can become server code execution.
The host runs a PHP version without the fixes available in supported releases. A server-side flaw may remain exploitable despite updated WordPress code.
A subsite user reaches network-level settings or another site's content. One tenant may affect the wider WordPress network.
Site files or directories are writable by more users or processes than needed. An attacker with limited access may alter code or content.
A copied configuration file is served as plain text from the web root. Database credentials and security keys may leak.
A database tool is reachable from the public internet without adequate controls. A second administrative surface may put site data at risk.
Multiple sites share writable files or database credentials. Compromise of one site may affect another.
A cache stores personalized or restricted output as a public response. One visitor may receive another user's content.