The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, to view logs.
References
Configurations
History
No history.
Information
Published : 2023-08-16 05:15
Updated : 2023-11-07 04:22
NVD link : CVE-2023-4374
Mitre link : CVE-2023-4374
CVE.ORG link : CVE-2023-4374
JSON object : View
Products Affected
froger
- wp_remote_users_sync
CWE
No CWE.