Beta

Report

Acnoo Flutter API <= 1.0.5 is vulnerable to Account Takeover vulnerability

Unauthenticated
Published
2024-10-24

The Acnoo Flutter API plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.0.5. This is due to the plugin not properly verifying a users identify prior to allowing them to access an account. This makes it possible for unauthenticated attackers to log in as other users, such as administrators.

CVSS

Score:9.8

Severity:Critical

Version: 1.0.5

The plugin vendor has not patched this vulnerability at the moment.