WordPress Security

Guide tag · 100 matching pages

Wordpress Alert: XML-RPC login abuse

Repeated authentication attempts arrive through XML-RPC on a site that exposes it. Attackers may test credentials through a second login surface.

Wordpress Alert: Writable theme or plugin editor abuse

A compromised administrator account edits executable site files from the dashboard. Malicious code can persist in a theme or plugin.

Wordpress Alert: Webhook signature validation failures

An integration accepts incoming webhook data without verifying its signature. A forged notification may trigger order or account actions.

Wordpress Alert: Webhook endpoint authorization bypass

An incoming webhook route trusts a request without authenticating its sender. External callers may trigger automation or data changes.

Wordpress Alert: Weak password-reset tokens

A custom reset flow uses predictable, reusable, or long-lived tokens. Someone who obtains or guesses a token may reset another person's password.

Wordpress Alert: Vulnerable abandoned plugins

An installed plugin no longer receives security fixes. A known flaw can remain reachable indefinitely.

Wordpress Alert: Unprotected admin-post.php actions

A form handler trusts a submitted request without authorizing the user. A crafted request can change settings or content.

Wordpress Alert: Unprotected admin-ajax.php actions

A plugin AJAX action changes data without checking the caller's capability. An anonymous or low-privilege request may trigger the action.

Wordpress Alert: Unauthorized user creation

A registration or import action creates accounts without the intended authorization. Attackers may create access paths or hidden administrators.

Wordpress Alert: Unauthorized theme installation

A theme-management endpoint accepts a user without installation rights. Attacker-controlled theme code could be installed if other safeguards fail.

Wordpress Alert: Unauthorized settings changes

A low-privilege request updates site options or plugin configuration. Security controls, destinations, or site behavior may be changed.

Wordpress Alert: Unauthorized role changes

A settings or profile request changes a user's capabilities unexpectedly. An attacker may gain more access or remove a defender's access.

Wordpress Alert: Unauthorized price changes

A product endpoint accepts edits from a user without catalog rights. Products may be sold at unintended prices.

Wordpress Alert: Unauthorized post publication

A contributor-level action publishes content despite editorial restrictions. Unreviewed or malicious material can go live.

Wordpress Alert: Unauthorized plugin activation

A nonadministrator can activate installed code through a plugin or API flaw. New functionality may run with broad site privileges.

Wordpress Alert: Unauthenticated REST endpoint access

A custom REST route returns private records or performs changes for a signed-out visitor. Data may leak or site state may change without an account.

Wordpress Alert: Unauthenticated arbitrary file upload

A public form accepts a file type or location it should reject. The uploaded file may expose users or, in some configurations, execute server code.

Wordpress Alert: Two-factor authentication bypass in plugins

A third-party login route accepts a password without enforcing the site's second factor. A stolen password may become sufficient for account access.

Wordpress Alert: Subscription ownership bypass

A customer can change another customer's subscription identifier in a request. Billing or subscription settings may be altered across accounts.

Wordpress Alert: Subscriber-to-administrator privilege escalation

A subscriber can change their role or call a privileged plugin action. A basic account may become a site administrator.