The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://wordpress.org/plugins/wp-central/#developers | release notes |
https://plugins.trac.wordpress.org/changeset?&old=2244363%40wp-central&new=2244363%40wp-central | patch third party advisory release notes |
https://wpvulndb.com/vulnerabilities/10074 | third party advisory exploit |