iThemes Sync <= 2.0.17 - Authentication Bypass

2019-10-09 00:00
Anonymous

Vulnerability Overview

The iThemes Sync plugin for WordPress is vulnerable to authentication bypass due to a missing validation on the secure key in versions up to, and including, 2.0.17. This makes it possible for unauthenticated attackers to add their own secure key leading to a complete compromise of the affected website.

Technical Analysis

REMEDIATION: Update to version 2.0.18, or a newer patched version --- IDENTIFIER: CWE-286 (Incorrect User Management) The product does not properly manage a user within its environment.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C