Improper access control in wpCentral - CVE-2020-9043
Published: February 18, 2020
wpCentral
Detailed vulnerability description
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in place to protect the connection key as it was displayed in the "admin_footer" in a modal dialog. A remote authenticated attacker can bypass implemented security restrictions and gain administrator access to the application.