Mistape 1.4.0 - Backdoor
criticalThe Mistape plugin for WordPress is vulnerable to a developer-created backdoor in version 1.4.0. The backdoor is present in the report_stats() function, when the 'cmb' parameter is set to 'user', the plugin then looks for the first administrative user in the database and logs the person making the request in as that us...
- CVSS:
- 9.8
- Affected:
- 1.4.0 – 1.4.0
- Fix:
- No patched version reported
- Disclosed:
- Feb 28, 2022