Wordpress Alert: Webhook endpoint authorization bypass

An incoming webhook route trusts a request without authenticating its sender. External callers may trigger automation or data changes.

What it looks like

An incoming webhook route trusts a request without authenticating its sender.

Why it matters

External callers may trigger automation or data changes.

What to check

Verify signatures or another documented authentication method on inbound hooks.

Documentation

This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WooCommerce webhooks, WordPress REST endpoint permissions.