cleantalk
Vulnerabilities and Security Researches

Make Connector, 1276509fccb388cdaad040b2addd7e6fad6e40ce

Application

Make Connector

Published on
Sep 26, 2022
Research Description
Make Connector [integromat-connector] < 1.5.3 Make, formerly Integromat Connector <= 1.5.2 - Authenticated (Subscriber+) Information Disclosure The Make plugin for WordPress is vulnerable to authorization bypass due to a missing capability check and nonce verification on an admin_menu action in versions up to, and including, 1.5.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to download the plugin's logs which may contain sensitive information.
Affected versions
Min -, max 1.5.3.
Status
vulnerable