Web / CMS
Authentication & Access Bypass
WPCode <= 2.0.6 - Contributor+ WPCode.com Library Connection Modification
WPCode <= 2.0.6 – Contributor+ WPCode.com Library Connection Modification The plugin does not have adequate privilege checks in place for several AJAX actions, only checking the nonce.
.png)
Overview
WPCode <= 2.0.6 – Contributor+ WPCode.com Library Connection Modification
The plugin does not have adequate privilege checks in place for several AJAX actions, only checking the nonce. This may lead to allowing any authenticated user who can edit posts to call the endpoints related to WPCode Library authentication (such as update and delete the auth key).
Vulnerability details
WPCode <= 2.0.6 – Contributor+ WPCode.com Library Connection Modification The plugin does not have adequate privilege checks in place for several AJAX actions, only checking the nonce.
Disclosure timeline
2023-01-10 Reported On
2023-02-09 Made Public On
2023-02-07 Fixed On
References
Credits
Sanjay Das
















