WordPress Security

Guide tag · 100 matching pages

Wordpress Alert: Malicious nulled themes or plugins

A pirated package contains hidden code or a modified updater. It may create a backdoor or steal data.

Wordpress Alert: Local file inclusion in themes

A theme selects a PHP template from untrusted input. A readable file outside the expected theme path may be included.

Wordpress Alert: LMS course access bypass

A course route exposes lessons to a user who has not enrolled. Paid or restricted learning material may leak.

Wordpress Alert: Insecure file permissions

Site files or directories are writable by more users or processes than needed. An attacker with limited access may alter code or content.

Wordpress Alert: Insecure direct object references in plugins

Changing a record ID exposes another user's booking, form entry, or file. Private information crosses account boundaries.

Wordpress Alert: Gift-card balance manipulation

A gift-card extension trusts balance changes from an unauthorized request. Store credit may be created or spent improperly.

Wordpress Alert: Form submission data leakage

A form endpoint exposes saved entries beyond the intended staff roles. Contact details or confidential messages may leak.

Wordpress Alert: Exposed wp-config.php backups

A copied configuration file is served as plain text from the web root. Database credentials and security keys may leak.

Wordpress Alert: Exposed migration archives

A migration package remains publicly downloadable after a move. It may contain database data and configuration secrets.

Wordpress Alert: Exposed custom REST routes

A plugin registers a route that discloses internal data or actions more broadly than intended. Remote callers may reach functionality that was assumed to be private.

Wordpress Alert: Exposed API keys in plugin settings

A plugin renders a secret in a public page, response, or log. Third parties may call connected services or APIs.

Wordpress Alert: Executable files disguised as images

An upload accepts a file based only on its name or claimed content type. A script may be stored where it can be executed or served to visitors.

Wordpress Alert: Event-registration data exposure

An event plugin lists attendee details to the wrong users. Names and contact information may be disclosed.

Wordpress Alert: Email-header injection in contact forms

A contact form accepts newline or header syntax in email fields. Messages may gain unintended recipients or headers.

Wordpress Alert: Draft content disclosure

Unpublished drafts appear in a public response or cached page. Embargoed or incomplete material can leak.

Wordpress Alert: DOM-based cross-site scripting in page builders

Builder JavaScript inserts untrusted URL or content data into the page unsafely. The browser executes script even if the server response is static.

Wordpress Alert: Database administration panels left exposed

A database tool is reachable from the public internet without adequate controls. A second administrative surface may put site data at risk.

Wordpress Alert: Customer data disclosure

An API or plugin returns customer records to an unauthorized caller. Personal and purchase information may be exposed.

Wordpress Alert: Cross-site request forgery against user management

An external page induces an authenticated administrator to change an account. Users or roles may be created, deleted, or changed.

Wordpress Alert: Cross-site request forgery against settings

A signed-in administrator visits an external page that triggers a settings change. Configuration may change without the administrator intending it.