WordPress Security

Guide tag · 100 matching pages

Wordpress Alert: Remote file inclusion in plugins

A plugin includes code from a URL or untrusted location. Attacker-controlled code may run if the runtime and plugin permit it.

Wordpress Alert: Reflected cross-site scripting in search

A crafted search URL echoes unsafe text into the page. A visitor following the link may execute attacker-controlled script.

Wordpress Alert: Publicly accessible database backups

A database dump sits under a web-accessible directory. Visitors may download user and site data.

Wordpress Alert: Public .git directories

A deployed repository directory is web-accessible. Source code and sometimes secrets may be retrievable.

Wordpress Alert: Public debug logs containing secrets

A debug or error log can be downloaded by visitors. Stack traces, tokens, or personal data may be exposed.

Wordpress Alert: Private post access bypass

A route or plugin reveals a post marked private to an unauthorized visitor. Restricted content becomes publicly accessible.

Wordpress Alert: PHP object injection through unsafe deserialization

A plugin unserializes untrusted input into PHP objects. Available object behaviors may be abused, sometimes with severe consequences.

Wordpress Alert: PHP execution inside upload directories

The web server executes scripts stored in uploads. An upload flaw can become server code execution.

Wordpress Alert: Payment status spoofing

A payment integration accepts an unverified completion signal. An unpaid order may appear paid or be fulfilled.

Wordpress Alert: Password spraying against WordPress logins

One or a few common passwords are tried across many accounts. A weak account may be taken over without a large attack volume per user.

Wordpress Alert: Password-reset link disclosure

Reset URLs appear in logs, analytics, or unintended messages. Anyone with a valid link may take over the account before it expires.

Wordpress Alert: Paid-download authorization bypass

A file link works without checking purchase or membership rights. Paid files may be shared publicly.

Wordpress Alert: Page-template local file inclusion (CVE-2026-87902)

An affected version and the advisory's theme and server preconditions allow an unexpected local PHP file to be included. Under those conditions, unauthenticated code execution may follow.

Wordpress Alert: Outdated PHP runtime vulnerabilities

The host runs a PHP version without the fixes available in supported releases. A server-side flaw may remain exploitable despite updated WordPress code.

Wordpress Alert: Order record access bypass

A customer can view or alter an order that is not theirs. Names, addresses, and purchase details may leak.

Wordpress Alert: OAuth account-linking flaws

A social-login integration links a local account to the wrong external identity. An attacker may gain access to another user's WordPress account.

Wordpress Alert: Multisite tenant isolation bypass

A subsite user reaches network-level settings or another site's content. One tenant may affect the wider WordPress network.

Wordpress Alert: Membership access bypass

A paid-content route checks login state but not membership entitlement. Nonmembers may read or download restricted material.

Wordpress Alert: Media-library access bypass

A user can read or change attachments outside their permitted scope. Private files or other authors' media may be affected.

Wordpress Alert: Malicious redirects through open-redirect flaws

A site link forwards visitors to an attacker-chosen destination. The trusted domain can be used in phishing links.