Wordapp <= 1.6.0 - Authorization Bypass through Use of Insufficiently Unique Cryptographic Signature

2023-05-30 00:00
István Márton

Strategic Overview

Status
Patched in 1.7.0
Affected PluginWordapp
Affected Version<= 1.6.0
CVSS9.8Critical
CVECVE-2023-2987
View all Wordapp vulnerabilities

Vulnerability Overview

The Wordapp plugin for WordPress is vulnerable to authorization bypass due to an use of insufficiently unique cryptographic signature on the 'wa_pdx_op_config_set' function in versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to the plugin to change the 'validation_token' in the plugin config, providing access to the plugin's remote control functionalities, such as creating an admin access URL, which can be used for privilege escalation.

Technical Analysis

REMEDIATION: Update to version 1.7.0, or a newer patched version --- IDENTIFIER: CWE-345 (Insufficient Verification of Data Authenticity) The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C