Wordpress Alert: Cache poisoning that exposes private pages
A cache stores personalized or restricted output as a public response. One visitor may receive another user's content.
What it looks like
A cache stores personalized or restricted output as a public response.
Why it matters
One visitor may receive another user's content.
What to check
Check cache rules for logged-in sessions, private routes, and preview URLs.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP web cache security guidance.
- Categories: WordPress
- Tags: #WordPress Security, #Hosting Security