iThemes Sync <= 2.0.17 - Authentication Bypass
2019-10-09 00:00
AnonymousStrategic Overview
StatusPatched in 2.0.18
Affected Version
< 2.0.18CVSS9.8Critical
CVE
N/AVulnerability Overview
The iThemes Sync plugin for WordPress is vulnerable to authentication bypass due to a missing validation on the secure key in versions up to, and including, 2.0.17. This makes it possible for unauthenticated attackers to add their own secure key leading to a complete compromise of the affected website.
Technical Analysis
REMEDIATION: Update to version 2.0.18, or a newer patched version --- IDENTIFIER: CWE-286 (Incorrect User Management) The product does not properly manage a user within its environment.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C