Wordpress Alert: Insecure direct object references in plugins
Changing a record ID exposes another user's booking, form entry, or file. Private information crosses account boundaries.
What it looks like
Changing a record ID exposes another user's booking, form entry, or file.
Why it matters
Private information crosses account boundaries.
What to check
Test object ownership checks in installed plugins' read, update, and delete flows.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress REST endpoint permissions, WordPress roles and capabilities.
- Categories: WordPress
- Tags: #WordPress Security, #Access Control