Various Newfold Plugins Various Versions - Unauthenticated Authentication Bypass via Bearer Token Validation with Empty Secret
highSeveral Newfold plugins are vulnerable to Authentication Bypass. The vulnerability exists because the plugins bundle the wp-module-data module. In the module, the `authenticate()` method — registered on the `rest_authentication_errors` filter and therefore evaluated for every unauthenticated REST API request — performs...
- CVSS:
- 8.8 (Wordfence)
- Affected:
- up to 2.3.5
- Fixed in:
- 2.3.6
- Disclosed:
- Sep 8, 2026