Unauthorized Data Access in WP Remote Users Sync Plugin for WordPress
CVE-2023-4374
4.3MEDIUM
What is CVE-2023-4374?
The WP Remote Users Sync plugin for WordPress is susceptible to unauthorized data access due to a missing capability check in the 'refresh_logs_async' function. This vulnerability impacts versions up to 1.2.11 and allows authenticated users with subscriber privileges or higher to access sensitive logs, potentially leading to unauthorized viewing and manipulation of data.
Affected Version(s)
WP Remote Users Sync * <= 1.2.11