plugin-icon

Balada Fix

Von vladanrs·
Blocks unauthenticated access to vulnerable REST paths. Add paths in Settings → Balada Fix. Only admins can use them.
Bewertungen
5
Version
1.1.0
Aktive Installationen
10
Zuletzt aktualisiert
Mar 26, 2026

Balada Fix protects your site from unauthenticated abuse of specific WordPress REST API endpoints. Such endpoints (for example the tagDiv theme’s wp-json/tdw/save_css) are often targeted by the „Balada Injector“ and similar campaigns to inject malicious scripts.

  • Add one or more REST path patterns in Settings Balada Fix (one per line).
  • Only logged-in administrators with the edit_theme_options capability can access those paths.
  • Unauthenticated or unauthorized requests receive a 403 Forbidden response.

Default protected path: tdw/save_css (tagDiv / Newspaper theme vulnerability).

Kostenlosmit kostenpflichtigen Tarifen
Mit deiner Installation stimmst du den Geschäftsbedingungen von WordPress.com sowie den Bedingungen für Drittanbieter-Plugins zu.
Getestet bis
WordPress 6.9.4
Dieses Plugin steht für deine -Website zum Download zur Verfügung.