Wordpress Alert: Server-side template injection

A theme or builder evaluates user-controlled text as a template. Template capabilities may disclose data or run unintended operations.

What it looks like

A theme or builder evaluates user-controlled text as a template.

Why it matters

Template capabilities may disclose data or run unintended operations.

What to check

Keep user content as data and review template evaluation paths.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP injection prevention.