What the vulnerability does
01Description
Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a through 4.2.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Improper Authentication vulnerability in WPMU DEV Defender Security allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Defender Security: from n/a through 4.2.0.
Explanation of Vulnerability in Simple Terms
Defender Security for WordPress contains an authentication flaw that allows unauthenticated attackers to read sensitive information from the site. The vulnerability affects versions up to 4.2.0 and requires no user interaction. Site administrators should update to a version newer than 4.2.0 to resolve this issue.
What an attacker can do
Read sensitive information from the site without logging in.
Potential impact on your site
Attackers can access confidential data exposed by the plugin without needing valid credentials.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities