The Syncee WordPress plugin before 1.0.10 leaks the administrator token that can be used to take over the administrators account.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Syncee_-_global_dropshipping |
Syncee |
* |
1.0.10 (excluding) |
References