Wordpress Alert: Multisite tenant isolation bypass

A subsite user reaches network-level settings or another site's content. One tenant may affect the wider WordPress network.

What it looks like

A subsite user reaches network-level settings or another site's content.

Why it matters

One tenant may affect the wider WordPress network.

What to check

Review multisite plugin permissions and network-only actions.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress roles and capabilities, WordPress REST endpoint permissions.