Wordpress Alert: REST API mass assignment
A REST update accepts fields the current user should not control, such as role or ownership. An ordinary edit can become a privilege or content-ownership change.
What it looks like
A REST update accepts fields the current user should not control, such as role or ownership.
Why it matters
An ordinary edit can become a privilege or content-ownership change.
What to check
Allowlist writable fields and verify permissions on each sensitive field.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress REST endpoint permissions, WordPress roles and capabilities.
- Categories: WordPress
- Tags: #WordPress Security, #Core Security