Lockdown Ledger
Lockdown Ledger
@LockdownLedger

Myth-Busting SOP: 'Editors Are Safe, Only Admins Are Dangerous'

Myth-Busting SOP: 'Editors Are Safe, Only Admins Are Dangerous'

The Editor role can publish unfiltered HTML, embed scripts via certain plugins, and pivot through file-upload flaws. Over-privileged 'safe' roles are how breaches spread laterally. Audit by capability:

— Step 1: List every role and its actual capabilities with a role-editor view, not the label.
— Step 2: Strip unfiltered_html from non-admins (it's off by default in multisite — match that).
— Step 3: Give contributors the lowest role that lets them do the job; create custom roles if needed.
— Step 4: Separate the daily-driver account from the super-admin account for every person.
— Step 5: Verify by logging in as each role and attempting a privileged action — it must fail.

Least privilege means capabilities, not job titles. Run this every time.
Этот пост опубликован в Telegram-канале Lockdown Ledger. Подписаться можно по ссылке: @LockdownLedger.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.