Wordpress Alert: Unprotected admin-post.php actions

A form handler trusts a submitted request without authorizing the user. A crafted request can change settings or content.

What it looks like

A form handler trusts a submitted request without authorizing the user.

Why it matters

A crafted request can change settings or content.

What to check

Check each admin-post handler for capability checks and a nonce where appropriate.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress roles and capabilities, WordPress nonces.