The Syncee WordPress plugin before 1.0.10 leaks the administrator token that can be used to take over the administrators account.
Affected Software
| Name | Vendor | Start Version | End Version |
|---|
| Syncee_-_global_dropshipping | Syncee | * | 1.0.10 (excluding) |
References