Wordpress Alert: Unprotected admin-ajax.php actions
A plugin AJAX action changes data without checking the caller's capability. An anonymous or low-privilege request may trigger the action.
What it looks like
A plugin AJAX action changes data without checking the caller's capability.
Why it matters
An anonymous or low-privilege request may trigger the action.
What to check
Review registered AJAX handlers for capability and intent checks.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress roles and capabilities, WordPress nonces.
- Categories: WordPress
- Tags: #WordPress Security, #Core Security