I made a custom rest endpoint in my wordpress site where i can make a post request from an app i made. How do i make this secure?

[ad_1]

Pretty vague question but since I have no idea yet about security… idk what exactly to ask.

What I know so far is that if the post request is also made within wordpress, I can verify it in my custom endpoint using something like wp_nonce. From what I know, its something that can be generated within wordpress. So my question now is, how do I verify posts requests to my custom rest endpoint that’s made outside of wordpress? Or what possible vulnerabilities/security issues, etc should i watch for?

I’ve heard about the CORS protection technique but from what I know that’s really easy to circumvent.

[ad_2]
4 Comments

 

This site will teach you how to build a WordPress website for beginners. We will cover everything from installing WordPress to adding pages, posts, and images to your site. You will learn how to customize your site with themes and plugins, as well as how to market your site online.

Buy WordPress Transfer