Security vulnerabilities in WPUmbrella (1)
-
Possible site takeover through stolen API credentials in combination with SQLi – (WPUmbrella <= 2.10.0)
WPUmbrella’s remote application uses a local companion plugin to perform its functionality. The communication between the remote WPUmbrella application and the WordPress site is secured using a shared secret stored as plaintext in the WordPress options table. An attacker that can read the plaintext value can fully impersonate WPUmbrella’s remote application and perform all actions,…