plugin

Wp Remote Users Sync Vulnerabilities

4 known security issues reported for the Wp Remote Users Sync WordPress plugin. Most recent disclosed Aug 16, 2023.

1 high 1 medium

Running Wp Remote Users Sync on your site? Check whether your installed version is affected.

Scan your site free

WP Remote Users Sync [wp-remote-users-sync] < 1.2.13

unknown

[en] The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' AJAX function in versions up to, and including, 1.2.12. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating f...

Affected:
up to 1.2.13
Fixed in:
1.2.13
Disclosed:
Aug 16, 2023

CVE-2023-3958 on NVD →

WP Remote Users Sync [wp-remote-users-sync] < 1.2.12

unknown

[en] The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, t...

Affected:
up to 1.2.12
Fixed in:
1.2.12
Disclosed:
Aug 16, 2023

CVE-2023-4374 on NVD →

WP Remote Users Sync <= 1.2.12 - Authenticated (Subscriber+) Server Side Request Forgery

high

The WP Remote Users Sync plugin for WordPress is vulnerable to Server Side Request Forgery via the 'notify_ping_remote' AJAX function in versions up to, and including, 1.2.12. This can allow authenticated attackers with subscriber-level permissions or above to make web requests to arbitrary locations originating from t...

CVSS:
8.5
Affected:
up to 1.2.12
Fixed in:
1.2.13
Disclosed:
Aug 15, 2023

CVE-2023-3958 on NVD →

WP Remote Users Sync <= 1.2.11 - Missing Authorization to Authenticated (Subscriber+) Log View

medium

The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, to vie...

CVSS:
4.3
Affected:
up to 1.2.11
Fixed in:
1.2.12
Disclosed:
Aug 15, 2023

CVE-2023-4374 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database