Clerk <= 3.8.2 - Authorization Bypass via Insufficient Validation
mediumThe Clerk plugin for WordPress is vulnerable to Authorization Bypass via Insufficient Validation in versions up to, and including, 3.8.2. This is due to the validation function for all API requests using comparison operators to verify API keys against those stored in the site options. This leaves the API request valid...
- CVSS:
- 5.6
- Affected:
- up to 3.8.2
- Fixed in:
- 3.8.3
- Disclosed:
- Nov 10, 2022