Authentication vulnerability in Staff / Employee Business Directory for Active Directory 1.2.3

The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to a security issue called LDAP Passback. This issue affects all versions up to and including 1.2.3. It occurs because the plugin does not properly validate when changing the LDAP server. This allows an attacker with administrative access to the website to change the LDAP server and collect the credentials from the original LDAP server.

Detected in:

Staff / Employee Business Directory for Active Directory fixed vulnerable versions: >= * <= 1.2.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.