plugin

Syncee For Suppliers Vulnerabilities

1 known security issue reported for the Syncee For Suppliers WordPress plugin. Most recent disclosed Oct 27, 2022.

1 medium

Running Syncee For Suppliers on your site? Check whether your installed version is affected.

Scan your site free

Syncee for Suppliers <= 1.0.5 - Missing Authorization to Sensitive Information Disclosure

medium

The Syncee for Suppliers plugin for WordPress is vulnerable to Missing Authorization to Sensitive Information Disclosure in versions up to, and including, 1.0.5. This is due to a missing capability check on the /wp-json/syncee/supplier/v1/getDataForFrontend REST-API endpoint. This makes it possible for unauthenticated...

CVSS:
5.3
Affected:
up to 1.0.5
Fixed in:
1.0.10
Disclosed:
Oct 27, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database