I Found Three Vulnerabilities in My Own Plugin Before Shipping It
Every AJAX handler in my plugin had a nonce check. Every one of them also verified manage_options. I’d been deliberate about that from the start, and when I sat down to do a security pass before submitting to WordPress.org, I expected it to be a formality. It wasn’t. I found two high-severity issues and one … Read more