VYPR

Webo-facto

by WordPress

Source repositories

CVEs (1)

  • CVE-2024-8853CriSep 20, 2024
    risk 0.57cvss 9.8epss 0.01

    The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by…