Wordpress Alert: Exposed custom REST routes

A plugin registers a route that discloses internal data or actions more broadly than intended. Remote callers may reach functionality that was assumed to be private.

What it looks like

A plugin registers a route that discloses internal data or actions more broadly than intended.

Why it matters

Remote callers may reach functionality that was assumed to be private.

What to check

List plugin routes and review the data returned and the permission callback for each one.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress REST endpoint permissions.