Hosting Security

Guide tag · 10 matching pages

Wordpress Alert: Public .git directories

A deployed repository directory is web-accessible. Source code and sometimes secrets may be retrievable.

Wordpress Alert: Public debug logs containing secrets

A debug or error log can be downloaded by visitors. Stack traces, tokens, or personal data may be exposed.

Wordpress Alert: PHP execution inside upload directories

The web server executes scripts stored in uploads. An upload flaw can become server code execution.

Wordpress Alert: Outdated PHP runtime vulnerabilities

The host runs a PHP version without the fixes available in supported releases. A server-side flaw may remain exploitable despite updated WordPress code.

Wordpress Alert: Multisite tenant isolation bypass

A subsite user reaches network-level settings or another site's content. One tenant may affect the wider WordPress network.

Wordpress Alert: Insecure file permissions

Site files or directories are writable by more users or processes than needed. An attacker with limited access may alter code or content.

Wordpress Alert: Exposed wp-config.php backups

A copied configuration file is served as plain text from the web root. Database credentials and security keys may leak.

Wordpress Alert: Database administration panels left exposed

A database tool is reachable from the public internet without adequate controls. A second administrative surface may put site data at risk.

Wordpress Alert: Cross-site contamination on shared hosting

Multiple sites share writable files or database credentials. Compromise of one site may affect another.

Wordpress Alert: Cache poisoning that exposes private pages

A cache stores personalized or restricted output as a public response. One visitor may receive another user's content.