Wordpress Alert: Session fixation

A session identifier survives the transition from signed-out to signed-in state. A person who knows the identifier may inherit the authenticated session.

What it looks like

A session identifier survives the transition from signed-out to signed-in state.

Why it matters

A person who knows the identifier may inherit the authenticated session.

What to check

Review custom session handling and verify identifiers rotate after login.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See OWASP session management guidance.