Wordpress Alert: Unauthenticated REST endpoint access

A custom REST route returns private records or performs changes for a signed-out visitor. Data may leak or site state may change without an account.

What it looks like

A custom REST route returns private records or performs changes for a signed-out visitor.

Why it matters

Data may leak or site state may change without an account.

What to check

Inventory custom routes and verify their permission callbacks reject anonymous requests where access is private.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress REST endpoint permissions.