Description
The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, to view logs.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-54238 | The WP Remote Users Sync plugin for WordPress is vulnerable to unauthorized access of data and addition of data due to a missing capability check on the 'refresh_logs_async' functions in versions up to, and including, 1.2.11. This makes it possible for authenticated attackers with subscriber privileges or above, to view logs. |
References
History
Wed, 08 Apr 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | WP Remote Users Sync <= 1.2.11 - Missing Authorization to Authenticated (Subscriber+) Log View | |
| Weaknesses | CWE-862 |
Thu, 26 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T16:44:26.087Z
Reserved: 2023-08-15T15:36:00.226Z
Link: CVE-2023-4374
Updated: 2024-08-02T07:24:04.791Z
Status : Modified
Published: 2023-08-16T05:15:10.357
Modified: 2026-04-08T17:17:02.460
Link: CVE-2023-4374
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD