User Session Synchronizer WordPress Plugin Vulnerable to Authentication Bypass
- Severity
- CRITICAL
- CVSS
- 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Affected component
- user session synchronizer plugin (wordpress)
- Patched version
- Not yet available
The User Session Synchronizer plugin for WordPress is reportedly vulnerable to Authentication Bypass leading to Account Takeover in all versions up to, and including, 1.4.0.
What happened
The User Session Synchronizer plugin for WordPress is under investigation for a critical vulnerability that allows unauthenticated attackers to bypass authentication and take over accounts, including administrator accounts. This is due to the `synchronize_session()` function, which is executed on every request, failing to validate attacker-supplied parameters. When a specific parameter references an unregistered slot, the encryption key degrades to a predictable value, and the referer allowlist collapses to an empty-string match. This vulnerability affects all versions up to, and including, 1.4.0.
To assess your exposure, check if your WordPress site uses the User Session Synchronizer plugin and verify the version. If you are using version 1.4.0 or earlier, you are potentially affected. It is crucial to review your site access logs for any suspicious activity that may indicate an attempted or successful exploit.
What to do about it
- Check the version of the User Session Synchronizer plugin on your WordPress site.
- If you are using version 1.4.0 or earlier, upgrade to a version beyond 1.4.0 once it becomes available.
- Review your site access logs for any suspicious activity that may indicate an attempted or successful exploit.
- Monitor the primary sources for updates on a patched version.
- Consider implementing additional security measures to protect your WordPress site until a fix is released.
How 0Day would have caught this
user session synchronizer plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are potentially affected if your WordPress site uses the User Session Synchronizer plugin and the version is 1.4.0 or earlier.
What should I do right now?
Check the version of the plugin on your site. If you are using version 1.4.0 or earlier, upgrade to a version beyond 1.4.0 once it becomes available and review your site access logs for any suspicious activity.
Is there a patched version available?
No official fix has been published yet. Monitor the primary sources for updates on a patched version.
What is the severity of this vulnerability?
The severity of this vulnerability is CRITICAL with a CVSS score of 9.8.