WordPress Plugin Vulnerabilities

Breadcrumb NavXT < 6.2.0 - Username Disclosure via REST API

Description

The Breadcrumb NavXT WordPress plugin was affected by an Username Disclosure via REST API security vulnerability.

Proof of Concept

http://www.example.com/wp-json/bcn/v1/author/1

Affects Plugins

Fixed in 6.2.0

References

Miscellaneous

Original Researcher
Janek Vind "waraxe"
Submitter
Ryan Dewhurst
Submitter twitter
Verified
No

Timeline

Publicly Published
2018-09-28 (about 5 years ago)
Added
2018-09-28 (about 5 years ago)
Last Updated
2019-11-01 (about 4 years ago)

Other