What the vulnerability does
01Description
Authentication Bypass by Spoofing vulnerability in patreon Patreon WordPress patreon-connect.This issue affects Patreon WordPress: from n/a through <= 1.9.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Authentication Bypass by Spoofing vulnerability in patreon Patreon WordPress patreon-connect.This issue affects Patreon WordPress: from n/a through <= 1.9.0.
Explanation of Vulnerability in Simple Terms
The Patreon WordPress plugin through version 1.9.0 exposes sensitive information to unauthenticated attackers over the network. An attacker can read data that should be restricted, such as user details or configuration information. No user interaction or special privileges are required. Update the plugin immediately to a version newer than 1.9.0.
What an attacker can do
Read sensitive information from the site without logging in.
Potential impact on your site
Visitor data, user details, or plugin configuration may be exposed to anyone on the internet.
Conditions required to exploit
Network access to the site; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities