Wordpress Alert: Unauthorized plugin activation
A nonadministrator can activate installed code through a plugin or API flaw. New functionality may run with broad site privileges.
What it looks like
A nonadministrator can activate installed code through a plugin or API flaw.
Why it matters
New functionality may run with broad site privileges.
What to check
Review activation events and the capability checks on plugin-management actions.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress roles and capabilities.
- Categories: WordPress
- Tags: #WordPress Security, #Access Control