Record summary

CVE-2020-9043 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Dec 5, 2022 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryHIGHWordPress wpCentral <1.5.1 - Information DisclosureCVSS 8.8

WordPress wpCentral plugin before 1.5.1 is susceptible to information disclosure. An attacker can access the connection key for WordPress Admin account and thus potentially obtain sensitive information, modify data, and/or execute unauthorized operations.

Impact

An attacker can exploit this vulnerability to gain sensitive information from the wpCentral plugin.

Remediation

Update the wpCentral plugin to version 1.5.1 or later to fix the information disclosure vulnerability.

WeaknessesCWE-200
Authorsscent2d
Template tagscvecve2020wordpresswp-pluginwpcentralauthenticatedwpwpscanvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:wpcentral:wpcentral:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4