Improper Authentication in iThemes Sync - #VU21967
Published: October 21, 2019
iThemes Sync
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to insufficient secure key validation. A remote authenticated attacker can add his own “secure key” to a site with the sync plugin, bypass authentication process, gain unauthorized access to the application and perform arbitrary actions, such as Add/Remove plugins or themes on your sites, manipulate content on your sites or Add/Change/Remove users on your sites.
.