Wordpress Alert: Insecure file permissions

Site files or directories are writable by more users or processes than needed. An attacker with limited access may alter code or content.

What it looks like

Site files or directories are writable by more users or processes than needed.

Why it matters

An attacker with limited access may alter code or content.

What to check

Review ownership and permissions using the host's deployment model.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress hardening guide.