Wordable <= 3.1.1 - Authentication Bypass
criticalThe Wordable plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.1.1. This is due to the use of a user supplied hashing algorithm passed to the hash_hmac() function and the use of a loose comparison on the hash which allows an attacker to trick the function into thinking it h...
- CVSS:
- 9.8
- Affected:
- up to 3.1.2
- Fixed in:
- 3.1.2
- Disclosed:
- Jan 28, 2020