PT-2023-28959 · WordPress · Wp Remote Users Sync

István Márton

+1

·

Publicado

2023-08-15

·

Atualizado

2023-08-22

·

CVE-2023-4374

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions WP Remote Users Sync plugin for WordPress versions up to, and including, 1.2.11
Description The issue allows unauthorized access and addition of data due to a missing capability check on the refresh logs async function. This makes it possible for authenticated attackers with subscriber privileges or above to view logs.
Recommendations For WP Remote Users Sync plugin for WordPress versions up to, and including, 1.2.11, consider disabling the refresh logs async function until a patch is available to prevent unauthorized access and data addition. Restrict access to logs for users with subscriber privileges or above to minimize the risk of exploitation.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-4374

Produtos afetados

Wp Remote Users Sync