Wordpress Alert: Remote file inclusion in plugins
A plugin includes code from a URL or untrusted location. Attacker-controlled code may run if the runtime and plugin permit it.
Guide tag · 100 matching pages
A plugin includes code from a URL or untrusted location. Attacker-controlled code may run if the runtime and plugin permit it.
A crafted search URL echoes unsafe text into the page. A visitor following the link may execute attacker-controlled script.
A database dump sits under a web-accessible directory. Visitors may download user and site data.
A deployed repository directory is web-accessible. Source code and sometimes secrets may be retrievable.
A debug or error log can be downloaded by visitors. Stack traces, tokens, or personal data may be exposed.
A route or plugin reveals a post marked private to an unauthorized visitor. Restricted content becomes publicly accessible.
A plugin unserializes untrusted input into PHP objects. Available object behaviors may be abused, sometimes with severe consequences.
The web server executes scripts stored in uploads. An upload flaw can become server code execution.
A payment integration accepts an unverified completion signal. An unpaid order may appear paid or be fulfilled.
One or a few common passwords are tried across many accounts. A weak account may be taken over without a large attack volume per user.
Reset URLs appear in logs, analytics, or unintended messages. Anyone with a valid link may take over the account before it expires.
A file link works without checking purchase or membership rights. Paid files may be shared publicly.
An affected version and the advisory's theme and server preconditions allow an unexpected local PHP file to be included. Under those conditions, unauthenticated code execution may follow.
The host runs a PHP version without the fixes available in supported releases. A server-side flaw may remain exploitable despite updated WordPress code.
A customer can view or alter an order that is not theirs. Names, addresses, and purchase details may leak.
A social-login integration links a local account to the wrong external identity. An attacker may gain access to another user's WordPress account.
A subsite user reaches network-level settings or another site's content. One tenant may affect the wider WordPress network.
A paid-content route checks login state but not membership entitlement. Nonmembers may read or download restricted material.
A user can read or change attachments outside their permitted scope. Private files or other authors' media may be affected.
A site link forwards visitors to an attacker-chosen destination. The trusted domain can be used in phishing links.