Lucene search

K
wpvulndbWpvulndbWPVDB-ID:5A115979-3C70-43FE-85B3-E2008AF94D90
HistorySep 26, 2023 - 12:00 a.m.

Staff / Employee Business Directory for Active Directory < 1.3 - Admin LDAP Credentials Retrieval

2023-09-2600:00:00
wpscan.com
2
wordpress
active directory
ldap passback
vulnerable plugin
administrative access

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.6%

Description The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.

CPENameOperatorVersion
eq1.3

6.3 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

26.6%

Related for WPVDB-ID:5A115979-3C70-43FE-85B3-E2008AF94D90