Report
The Acnoo Flutter API plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.5. This is due to the plugin not properly verifying a users identify prior to allowing them to access an account. This makes it possible for unauthenticated attackers to log in as other users, such as administrators.
Score:9.8
Severity:Critical
Version: 1.0.5
The plugin vendor has not patched this vulnerability at the moment.