plugin

Mistape Vulnerabilities

1 known security issue reported for the Mistape WordPress plugin. Most recent disclosed Feb 28, 2022.

1 critical

Running Mistape on your site? Check whether your installed version is affected.

Scan your site free

Mistape 1.4.0 - Backdoor

critical

The Mistape plugin for WordPress is vulnerable to a developer-created backdoor in version 1.4.0. The backdoor is present in the report_stats() function, when the 'cmb' parameter is set to 'user', the plugin then looks for the first administrative user in the database and logs the person making the request in as that us...

CVSS:
9.8
Affected:
1.4.0 – 1.4.0
Fix:
No patched version reported
Disclosed:
Feb 28, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database