Authentication vulnerability in Bravis User 1.0.0

The Bravis User plugin for WordPress has a security issue that allows unauthorized access to administrative accounts. This vulnerability exists in all versions up to and including 1.0.0. The problem lies in the plugin not properly verifying user data through the facebook_ajax_login_callback() function. This means that attackers without valid credentials can log in as administrative users, as long as they have an existing account on the site and know the email of an administrative user.

Detected in:

Bravis User open vulnerable versions: >= * <= 1.0.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.