plugin

Authorizer Vulnerabilities

1 known security issue reported for the Authorizer WordPress plugin. Most recent disclosed Nov 1, 2022.

1 high

Running Authorizer on your site? Check whether your installed version is affected.

Scan your site free

phpCAS authentication library < 1.6.0 - Service Hostname Discovery Exploitation

high

The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows an attacker to control the host header and use a valid ticket granted for any authorized service in the same SSO realm (CAS server) to authenticate to the service protected by phpCAS. Depending on the settings of the...

CVSS:
8
Affected:
up to 1.6.0
Fixed in:
1.6.0
Disclosed:
Nov 1, 2022

CVE-2022-39369 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database