{"id":5347,"date":"2018-07-01T02:47:20","date_gmt":"2018-07-01T02:47:20","guid":{"rendered":"https:\/\/www.truehost.co.ke\/support\/?post_type=ht_kb&#038;p=5347"},"modified":"2024-06-21T08:31:31","modified_gmt":"2024-06-21T08:31:31","password":"","slug":"vulnerability-types-wordpress-plugins","status":"publish","type":"docs","link":"https:\/\/truehost.com\/support\/knowledge-base\/vulnerability-types-wordpress-plugins\/","title":{"rendered":"Vulnerability types with WordPress plugins"},"content":{"rendered":"<p>Some plugins in WordPress CMS are vulnerable and allow unauthorised activity in your hosting account such as spam, unauthorised access etc. We have a list of such know plugins in another article. Have a look at those plugins too and remove them if you have them. Such plugins need to be Deactivated and Deleted from your WordPress account.<\/p>\n<p><strong>Below is a list of vulnerabilities in the plugins:<\/strong><\/p>\n<p><strong>1. <\/strong><strong>Arbitrary file viewing<\/strong><br \/>\nThis allow the attacker to view files in your account including those with sensitive information such as wp-config.php<\/p>\n<p><strong>2. <\/strong><strong>Arbitrary file upload<\/strong><br \/>\nThis allows the upload of files that can executed on to do almost anything on the account ranging from spamming, to redirection of site, running of a resource intensive program eg cnrig among other things.<\/p>\n<p><strong>Privilege escalation<\/strong><br \/>\nHere, an attacker is able to create an account in your dashboard. The attacker can then escalate the privileges of the account say from subscriber to administrator<\/p>\n<p><strong>SQL injection<\/strong><br \/>\nBy not escaping and filtering data that goes into SQL queries, malicious code can be injected into queries and data deleted, updated or inserted into the database. This is one of the most common vulnerabilities.<\/p>\n<p><strong>Remote code execution (RCE)<\/strong><br \/>\nInstead of uploading and running malicious code, the attacker can run it from a remote location. The code can do anything, from hijacking the site to completely deleting it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some plugins in WordPress CMS are vulnerable and allow unauthorised activity in your hosting account such as spam, unauthorised access etc. We have a list of such know plugins in another article. Have a look at those plugins too and remove them if you have them. Such plugins need to be Deactivated and Deleted from [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"_eb_attr":"","_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0,"footnotes":""},"doc_category":[1838],"doc_tag":[],"class_list":["post-5347","docs","type-docs","status-publish","hentry","doc_category-wordpress"],"year_month":"2026-06","word_count":226,"total_views":0,"reactions":{"happy":0,"normal":0,"sad":0},"author_info":{"name":"w m","author_nicename":"wm","author_url":"https:\/\/truehost.com\/support\/author\/wm\/"},"doc_category_info":[{"term_name":"WordPress","term_url":"https:\/\/truehost.com\/support\/docs-category\/wordpress\/"}],"doc_tag_info":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Vulnerability types with Wordpress plugins -<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.truehost.com\/support\/knowledge-base\/vulnerability-types-wordpress-plugins\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Vulnerability types with Wordpress plugins -\" \/>\n<meta property=\"og:description\" content=\"Some plugins in WordPress CMS are vulnerable and allow unauthorised activity in your hosting account such as spam, unauthorised access etc. We have a list of such know plugins in another article. Have a look at those plugins too and remove them if you have them. Such plugins need to be Deactivated and Deleted from [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.truehost.com\/support\/knowledge-base\/vulnerability-types-wordpress-plugins\/\" \/>\n<meta property=\"article:modified_time\" content=\"2024-06-21T08:31:31+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"1 minute\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.truehost.com\\\/support\\\/knowledge-base\\\/vulnerability-types-wordpress-plugins\\\/\",\"url\":\"https:\\\/\\\/www.truehost.com\\\/support\\\/knowledge-base\\\/vulnerability-types-wordpress-plugins\\\/\",\"name\":\"Vulnerability types with Wordpress plugins -\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truehost.com\\\/support\\\/#website\"},\"datePublished\":\"2018-07-01T02:47:20+00:00\",\"dateModified\":\"2024-06-21T08:31:31+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.truehost.com\\\/support\\\/knowledge-base\\\/vulnerability-types-wordpress-plugins\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.truehost.com\\\/support\\\/knowledge-base\\\/vulnerability-types-wordpress-plugins\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.truehost.com\\\/support\\\/knowledge-base\\\/vulnerability-types-wordpress-plugins\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truehost.com\\\/support\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Vulnerability types with WordPress plugins\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truehost.com\\\/support\\\/#website\",\"url\":\"https:\\\/\\\/truehost.com\\\/support\\\/\",\"name\":\"\",\"description\":\"Help In a Click\",\"publisher\":{\"@id\":\"https:\\\/\\\/truehost.com\\\/support\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truehost.com\\\/support\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truehost.com\\\/support\\\/#organization\",\"name\":\"Truehost Kenya\",\"url\":\"https:\\\/\\\/truehost.com\\\/support\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/truehost.com\\\/support\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truehost.com\\\/support\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/cropped-image_2026-04-16_174808866.png\",\"contentUrl\":\"https:\\\/\\\/truehost.com\\\/support\\\/wp-content\\\/uploads\\\/2026\\\/04\\\/cropped-image_2026-04-16_174808866.png\",\"width\":240,\"height\":48,\"caption\":\"Truehost Kenya\"},\"image\":{\"@id\":\"https:\\\/\\\/truehost.com\\\/support\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Vulnerability types with Wordpress plugins -","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.truehost.com\/support\/knowledge-base\/vulnerability-types-wordpress-plugins\/","og_locale":"en_US","og_type":"article","og_title":"Vulnerability types with Wordpress plugins -","og_description":"Some plugins in WordPress CMS are vulnerable and allow unauthorised activity in your hosting account such as spam, unauthorised access etc. We have a list of such know plugins in another article. Have a look at those plugins too and remove them if you have them. Such plugins need to be Deactivated and Deleted from [&hellip;]","og_url":"https:\/\/www.truehost.com\/support\/knowledge-base\/vulnerability-types-wordpress-plugins\/","article_modified_time":"2024-06-21T08:31:31+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"1 minute"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.truehost.com\/support\/knowledge-base\/vulnerability-types-wordpress-plugins\/","url":"https:\/\/www.truehost.com\/support\/knowledge-base\/vulnerability-types-wordpress-plugins\/","name":"Vulnerability types with Wordpress plugins -","isPartOf":{"@id":"https:\/\/truehost.com\/support\/#website"},"datePublished":"2018-07-01T02:47:20+00:00","dateModified":"2024-06-21T08:31:31+00:00","breadcrumb":{"@id":"https:\/\/www.truehost.com\/support\/knowledge-base\/vulnerability-types-wordpress-plugins\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.truehost.com\/support\/knowledge-base\/vulnerability-types-wordpress-plugins\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.truehost.com\/support\/knowledge-base\/vulnerability-types-wordpress-plugins\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truehost.com\/support\/"},{"@type":"ListItem","position":2,"name":"Vulnerability types with WordPress plugins"}]},{"@type":"WebSite","@id":"https:\/\/truehost.com\/support\/#website","url":"https:\/\/truehost.com\/support\/","name":"","description":"Help In a Click","publisher":{"@id":"https:\/\/truehost.com\/support\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truehost.com\/support\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/truehost.com\/support\/#organization","name":"Truehost Kenya","url":"https:\/\/truehost.com\/support\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/truehost.com\/support\/#\/schema\/logo\/image\/","url":"https:\/\/truehost.com\/support\/wp-content\/uploads\/2026\/04\/cropped-image_2026-04-16_174808866.png","contentUrl":"https:\/\/truehost.com\/support\/wp-content\/uploads\/2026\/04\/cropped-image_2026-04-16_174808866.png","width":240,"height":48,"caption":"Truehost Kenya"},"image":{"@id":"https:\/\/truehost.com\/support\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/truehost.com\/support\/wp-json\/wp\/v2\/docs\/5347","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truehost.com\/support\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/truehost.com\/support\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/truehost.com\/support\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/truehost.com\/support\/wp-json\/wp\/v2\/comments?post=5347"}],"version-history":[{"count":1,"href":"https:\/\/truehost.com\/support\/wp-json\/wp\/v2\/docs\/5347\/revisions"}],"predecessor-version":[{"id":5348,"href":"https:\/\/truehost.com\/support\/wp-json\/wp\/v2\/docs\/5347\/revisions\/5348"}],"wp:attachment":[{"href":"https:\/\/truehost.com\/support\/wp-json\/wp\/v2\/media?parent=5347"}],"wp:term":[{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/truehost.com\/support\/wp-json\/wp\/v2\/doc_category?post=5347"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/truehost.com\/support\/wp-json\/wp\/v2\/doc_tag?post=5347"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}