WP Guppy < 1.3 - Information Disclosure

2021-11-22 00:00
Keyvan Hardani

Strategic Overview

Status
Patched in 1.3
Affected PluginWP Guppy
Affected Version< 1.3
CVSS6.5Medium
CVECVE-2021-24997
View all WP Guppy vulnerabilities

Vulnerability Overview

The WP Guppy WordPress plugin before 1.3 does not have any authorisation in some of the REST API endpoints, allowing any user to call them which could lead to sensitive information disclosure, such as usernames and chats between users, as well as being able to send messages as an arbitrary user.

Technical Analysis

REMEDIATION: Update to version 1.3, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C