Wordpress Alert: Unprotected admin-post.php actions
A form handler trusts a submitted request without authorizing the user. A crafted request can change settings or content.
What it looks like
A form handler trusts a submitted request without authorizing the user.
Why it matters
A crafted request can change settings or content.
What to check
Check each admin-post handler for capability checks and a nonce where appropriate.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress roles and capabilities, WordPress nonces.
- Categories: WordPress
- Tags: #WordPress Security, #Core Security