Vulnerability Types
Plain-language explainers for the vulnerability classes that hit WordPress.
11
Guides
WP Activity Log before 4.1.5 unauthenticated SQLi
Status: patched. This is a fix-verified writeup of an unauthenticated SQL injection we originally disclosed in WP Activity Log (then WP Security Audit Log, now sold by Melapress)…
Remote Code Execution in WordPress, Explained
The worst class, how plugins get there, and why cleanup is not the same as patching.
CSRF in WordPress, Explained
Nonces, why plugins skip them, and how a “moderate” flaw reaches code execution.
Cross-Site Scripting (XSS) in WordPress, Explained
Stored, reflected and why “it only affects admins” is the wrong conclusion.
SQL Injection in WordPress, Explained
What SQL injection is, why WordPress plugins keep producing it, and what it means when your site has one.
WordPress and PHAR Unserialize: Why File Handling Can Become Code Risk
PHAR unserialize risk is about file operations becoming object-deserialization triggers. If a plugin lets attackers influence file paths, normal-looking checks can become dangerous.
WordPress and Multiple maybe_unserialize Calls: When Data Parsing Gets Risky
Repeated unserialization is a smell. If user-influenced data is parsed again and again, developers should ask whether the application is normalizing data or accidentally expanding attacker control.
WordPress Upload Any File with an Image Extension: Why Extension Checks Fail
A file ending in .jpg is not automatically an image. Upload security must validate content, storage location, execution rules, and user capability.
WordPress Null Byte to RCE: What an Old 0-Day Pattern Teaches Us
Null byte issues are old, but the lesson is current: never trust file names, extensions, or paths until the exact runtime behavior is understood.
WordPress Write Image to Any Directory RCE: File Writes and Code Execution
An arbitrary file write becomes urgent when attackers can choose both content and location. If executable paths are reachable, image handling can turn into code execution.