Wordpress Alert: Exposed API keys in plugin settings
A plugin renders a secret in a public page, response, or log. Third parties may call connected services or APIs.
What it looks like
A plugin renders a secret in a public page, response, or log.
Why it matters
Third parties may call connected services or APIs.
What to check
Inspect public output and rotate any exposed keys.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress REST authentication, WordPress hardening guide.
- Categories: WordPress
- Tags: #WordPress Security, #Integrations