Wordpress Alert: Media-library access bypass

A user can read or change attachments outside their permitted scope. Private files or other authors' media may be affected.

What it looks like

A user can read or change attachments outside their permitted scope.

Why it matters

Private files or other authors' media may be affected.

What to check

Review media endpoints for ownership and role checks.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress roles and capabilities, WordPress REST endpoint permissions.