plugin

Clerkio Vulnerabilities

1 known security issue reported for the Clerkio WordPress plugin. Most recent disclosed Nov 10, 2022.

1 medium

Running Clerkio on your site? Check whether your installed version is affected.

Scan your site free

Clerk <= 3.8.2 - Authorization Bypass via Insufficient Validation

medium

The Clerk plugin for WordPress is vulnerable to Authorization Bypass via Insufficient Validation in versions up to, and including, 3.8.2. This is due to the validation function for all API requests using comparison operators to verify API keys against those stored in the site options. This leaves the API request valid...

CVSS:
5.6
Affected:
up to 3.8.2
Fixed in:
3.8.3
Disclosed:
Nov 10, 2022

CVE-2022-3907 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database