Syncee for Suppliers <= 1.0.5 - Missing Authorization to Sensitive Information Disclosure

2022-10-27 00:00
Anonymous

Strategic Overview

Status
Patched in 1.0.10
Affected PluginSyncee for Suppliers
Affected Version<= 1.0.5
CVSS5.3Medium
CVEN/A
View all Syncee for Suppliers vulnerabilities

Vulnerability Overview

The Syncee for Suppliers plugin for WordPress is vulnerable to Missing Authorization to Sensitive Information Disclosure in versions up to, and including, 1.0.5. This is due to a missing capability check on the /wp-json/syncee/supplier/v1/getDataForFrontend REST-API endpoint. This makes it possible for unauthenticated attackers to perform a GET request to that information that discloses information like the site's syncee_access_token_supplier and data_to_syncee_installer_supplier values.

Technical Analysis

REMEDIATION: Update to version 1.0.10, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C