Wordpress Alert: REST API object authorization bypass
A logged-in user can retrieve or edit another user's resource by changing its identifier. Private records may be read or modified across accounts.
What it looks like
A logged-in user can retrieve or edit another user's resource by changing its identifier.
Why it matters
Private records may be read or modified across accounts.
What to check
Review both route-level capability checks and ownership checks on each object.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress REST endpoint permissions, WordPress roles and capabilities.
- Categories: WordPress
- Tags: #WordPress Security, #Core Security