Assumption Gapmedium riskhigh confidencecommunity validated

Hardcodes "admin@example.com" as admin check

Client-side role check trivially bypassed.

By Contributor · published 4/14/2026

Use user_roles + has_role().

Confidence check

Authorship · HumanHas anyone checked this? · community validatedConfidence · highEndorsements · 0Challenges · 0Evidence · 0Related guides · 0

Evidence

No evidence linked yet.

Discussion

0 comments

Loading comments…

Sign in to join the discussion.