WP SlackSync <= 1.8.5 - Sensitive Information Disclosure
highWP SlackSync plugin through 1.8.5 for WordPress leaks a Slack Access Token in source code. An attacker can obtain a lot of information about the victim's Slack (channels, members, etc.).
- CVSS:
- 8.6
- Affected:
- up to 1.8.6
- Fixed in:
- 1.8.6
- Disclosed:
- Nov 12, 2019