Syncee for Suppliers <= 1.0.5 - Missing Authorization to Sensitive Information Disclosure
mediumThe Syncee for Suppliers plugin for WordPress is vulnerable to Missing Authorization to Sensitive Information Disclosure in versions up to, and including, 1.0.5. This is due to a missing capability check on the /wp-json/syncee/supplier/v1/getDataForFrontend REST-API endpoint. This makes it possible for unauthenticated...
- CVSS:
- 5.3
- Affected:
- up to 1.0.5
- Fixed in:
- 1.0.10
- Disclosed:
- Oct 27, 2022