AccessAlly <= 3.5.6 - Information Exposure

2021-03-26 00:00
Till Krüss

Strategic Overview

Status
Patched in 3.5.7
Affected PluginAccessAlly
Affected Version<= 3.5.6
CVSS5.3Medium
CVECVE-2021-24226
View all AccessAlly vulnerabilities

Vulnerability Overview

In the AccessAlly WordPress plugin before 3.5.7, the file "resource/frontend/product/product-shortcode.php" responsible for the [accessally_order_form] shortcode is dumping serialize($_SERVER), which contains all environment variables. The leakage occurs on all public facing pages containing the [accessally_order_form] shortcode, no login or administrator role is required.

Technical Analysis

REMEDIATION: Update to version 3.5.7, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C