Impact
WP Synchro, a WordPress migration plugin, contains a subscriber bypass vulnerability that permits an attacker to circumvent two‑factor authentication. The flaw uses improper authentication checks, allowing the attacker to log in as any user without the standard password or token verification. This means an attacker can gain full control of the WordPress site once the bypass is executed. The weakness is classified as CWE‑290, a form of authentication bypass.
Affected Systems
WordPress sites that use WP Synchro, WP Migration Plugin DB & Files – WP Synchro, version 1.16.1 or earlier. The vulnerability is present in any installation of this plugin prior to the 1.16.2 release.
Risk and Exploitability
The CVSS score of 7.5 categorizes this as a high‑severity vulnerability. EPSS data is not available, and it is currently not listed in the CISA Known Exploited Vulnerabilities catalog. Based on the description, the attack vector is likely remote, targeting any user who can submit login requests. An attacker would need to know or guess a valid subscriber account to trigger the bypass but would gain full administrative rights once logged in. The lack of publicly disclosed exploits suggests moderate to low current exploitation risk, but the high severity warrants precautionary action.
OpenCVE Enrichment