Wordpress Alert: Unauthorized role changes
A settings or profile request changes a user's capabilities unexpectedly. An attacker may gain more access or remove a defender's access.
What it looks like
A settings or profile request changes a user's capabilities unexpectedly.
Why it matters
An attacker may gain more access or remove a defender's access.
What to check
Audit role-change events and protect every role update by capability and ownership checks.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress roles and capabilities.
- Categories: WordPress
- Tags: #WordPress Security, #Access Control