Wordpress Alert: Unauthorized theme installation

A theme-management endpoint accepts a user without installation rights. Attacker-controlled theme code could be installed if other safeguards fail.

What it looks like

A theme-management endpoint accepts a user without installation rights.

Why it matters

Attacker-controlled theme code could be installed if other safeguards fail.

What to check

Restrict theme installation to the appropriate capability and review installation history.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress roles and capabilities, WordPress hardening guide.