WP Remote Users Sync [wp-remote-users-sync] < 1.2.13
unknown
[en] The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' AJAX function in versions up to, and including, 1.2.12. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating f...
- Affected:
- up to 1.2.13
- Fixed in:
- 1.2.13
- Disclosed:
- Aug 16, 2023
CVE-2023-3958 on NVD →
WP Remote Users Sync [wp-remote-users-sync] < 1.2.12
unknown
[en] The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, t...
- Affected:
- up to 1.2.12
- Fixed in:
- 1.2.12
- Disclosed:
- Aug 16, 2023
CVE-2023-4374 on NVD →
WP Remote Users Sync <= 1.2.12 - Authenticated (Subscriber+) Server Side Request Forgery
high
The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' AJAX function in versions up to, and including, 1.2.12. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from t...
- CVSS:
- 8.5
- Affected:
- up to 1.2.12
- Fixed in:
- 1.2.13
- Disclosed:
- Aug 15, 2023
CVE-2023-3958 on NVD →
WP Remote Users Sync <= 1.2.11 - Missing Authorization to Authenticated (Subscriber+) Log View
medium
The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, to vie...
- CVSS:
- 4.3
- Affected:
- up to 1.2.11
- Fixed in:
- 1.2.12
- Disclosed:
- Aug 15, 2023
CVE-2023-4374 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database