Plugin Security

Guide tag · 10 matching pages

Wordpress Alert: Unauthorized post publication

A contributor-level action publishes content despite editorial restrictions. Unreviewed or malicious material can go live.

Wordpress Alert: Paid-download authorization bypass

A file link works without checking purchase or membership rights. Paid files may be shared publicly.

Wordpress Alert: Membership access bypass

A paid-content route checks login state but not membership entitlement. Nonmembers may read or download restricted material.

Wordpress Alert: Media-library access bypass

A user can read or change attachments outside their permitted scope. Private files or other authors' media may be affected.

Wordpress Alert: LMS course access bypass

A course route exposes lessons to a user who has not enrolled. Paid or restricted learning material may leak.

Wordpress Alert: Form submission data leakage

A form endpoint exposes saved entries beyond the intended staff roles. Contact details or confidential messages may leak.

Wordpress Alert: Event-registration data exposure

An event plugin lists attendee details to the wrong users. Names and contact information may be disclosed.

Wordpress Alert: Contact-form attachment disclosure

A form plugin stores uploaded attachments at guessable public URLs. Private submissions may be readable by anyone with the URL.

Wordpress Alert: Booking token disclosure

A booking link or token appears in a public response. Someone else may view or manage a reservation.

Wordpress Alert: Booking deletion without authorization

A booking plugin accepts a delete action from an unverified caller. Reservations may disappear or be canceled maliciously.