Wordpress Alert: Writable theme or plugin editor abuse
A compromised administrator account edits executable site files from the dashboard. Malicious code can persist in a theme or plugin.
What it looks like
A compromised administrator account edits executable site files from the dashboard.
Why it matters
Malicious code can persist in a theme or plugin.
What to check
Review file changes and consider disabling dashboard file editing where appropriate.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress hardening guide.
- Categories: WordPress
- Tags: #WordPress Security, #File Security