Wordpress Alert: Clickjacking of administrative actions

A third-party page frames an admin screen and tricks a user into clicking it. A legitimate session may carry out an unintended action.

What it looks like

A third-party page frames an admin screen and tricks a user into clicking it.

Why it matters

A legitimate session may carry out an unintended action.

What to check

Check framing protections and require intent checks for sensitive actions.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP clickjacking reference, WordPress nonces.