VYPR

Webo-facto

by WordPress

CVEs (1)

  • CVE-2024-8853Sep 20, 2024
    risk 0.00cvss epss 0.01

    The Webo-facto plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.40 due to insufficient restriction on the 'doSsoAuthentification' function. This makes it possible for unauthenticated attackers to make themselves administrators by…