Syncee – Global Dropshipping <= 1.0.9 - Missing Authorization.

2022-10-27 00:00
5h4m4n53c

Strategic Overview

Status
Patched in 1.0.10
Affected Version<= 1.0.9
CVSS4.3Medium
CVECVE-2022-3694
View all Syncee Premium Dropshipping & Wholesale vulnerabilities

Vulnerability Overview

The Syncee – Global Dropshipping plugin for WordPress is vulnerable to to Missing Authorization to Sensitive Information Disclosure in versions up to, and including, 1.0.9. This is due to a missing capability check on the /wp-json/syncee/supplier/v1/getDataForFrontend REST-API endpoint. This makes it possible for unauthenticated attackers to perform a GET request to that information that discloses information like the site's syncee_access_token and data_to_syncee_installer values.

Technical Analysis

REMEDIATION: Update to version 1.0.10, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C