Wordpress Alert: Unauthorized post publication
A contributor-level action publishes content despite editorial restrictions. Unreviewed or malicious material can go live.
Guide tag · 10 matching pages
A contributor-level action publishes content despite editorial restrictions. Unreviewed or malicious material can go live.
A file link works without checking purchase or membership rights. Paid files may be shared publicly.
A paid-content route checks login state but not membership entitlement. Nonmembers may read or download restricted material.
A user can read or change attachments outside their permitted scope. Private files or other authors' media may be affected.
A course route exposes lessons to a user who has not enrolled. Paid or restricted learning material may leak.
A form endpoint exposes saved entries beyond the intended staff roles. Contact details or confidential messages may leak.
An event plugin lists attendee details to the wrong users. Names and contact information may be disclosed.
A form plugin stores uploaded attachments at guessable public URLs. Private submissions may be readable by anyone with the URL.
A booking link or token appears in a public response. Someone else may view or manage a reservation.
A booking plugin accepts a delete action from an unverified caller. Reservations may disappear or be canceled maliciously.