Any customer can read and delete other customers’ form submissions
- Where
- A custom plugin’s AJAX actions:
admin-ajax.php?action=get_submission&id=1043 - What we found
- The action checks that you’re signed in, but not that the submission is yours. Changing the number returns anyone’s submission, and a second action deletes it.
- Why it matters
- Names, emails and messages from every customer were readable by any account holder. A scanner wouldn’t catch this; it needs a person who tries it.
- Fix applied
- Ownership and capability checks added to both actions, nonces enforced, and IDs replaced with unguessable tokens. Tested on staging, then deployed.
- Re-test
- Not reproducible with any test account. Closed.
Example finding, written for this page. It isn’t from a client report.
