The plugin leaks the administrator token that can be used to take over the administrator's account.
The plugin sends a GET request to "/wp-json/syncee/retailer/v1/getDataForFrontend" endpoint to get access token of the administrator. An attacker can use this access token to takeover the administrator's Syncee account via adding new team member.
5h4m4n53c
5h4m4n53c
Yes
2022-11-28 (about 4 months ago)
2022-11-14 (about 4 months ago)
2022-11-14 (about 4 months ago)