WordPress Plugin Vulnerabilities

ActivityPub for WordPress < 1.0.6 - Unauthenticated REST API Access

Description

The plugin does not properly authorize access to the REST API, allowing an unauthenticated attacker to access restricted endpoints.

Affects Plugins

Fixed in 1.0.6

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Rafie Muhammad
Verified
Yes

Timeline

Publicly Published
2024-01-05 (about 2 years ago)
Added
2024-01-12 (about 2 years ago)
Last Updated
2024-01-19 (about 2 years ago)

Other