mySites.guru - WordPress & Joomla Site Manager
I dug into the actual commit that fixed Joomla's com_ajax security gap (CVE-2026-21629). The fix uses PHP reflection to check for an AllowUnauthorizedAdministratorAccess attribute on every admin AJAX handler. No attribute = blocked. The problem: it's also an undocumented backwards-compatibility break. Plugins that rolled their own authentication (API keys, custom tokens) are now broken alongside plugins that had no auth at all. The release announcement doesn't mention it. The only documentation is buried in a known-issues sub-page. Also: Joomla's official AJAX example component (AjaxDemo) has zero security checks, and doesn't even use com_ajax. The AJAX plugin docs, com_ajax docs, and general AJAX docs all skip authentication and authorization entirely. Full analysis with code from the commit, five March 2026 CVEs, five more from the past year, and what extension developers need to change. https://mysites.guru/blog/ajax-endpoints-cms-security-blind-spot/?utm_source=facebook&utm_medium=social