Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2021-24148

Description

A business logic issue in the MStore API WordPress plugin, versions before 3.2.0, had an authentication bypass with Sign In With Apple allowing unauthenticated users to recover an authentication cookie with only an email address.

POC

Reference

- https://wpscan.com/vulnerability/bf5ddc43-974d-41fa-8276-c1a27d3cc882

Github

- https://github.com/20142995/nuclei-templates