Wordpress Alert: Unauthenticated REST endpoint access
A custom REST route returns private records or performs changes for a signed-out visitor. Data may leak or site state may change without an account.
What it looks like
A custom REST route returns private records or performs changes for a signed-out visitor.
Why it matters
Data may leak or site state may change without an account.
What to check
Inventory custom routes and verify their permission callbacks reject anonymous requests where access is private.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress REST endpoint permissions.
- Categories: WordPress
- Tags: #WordPress Security, #Core Security