← WordPress Vulnerabilities
WordPress security by component

WP Remote Users Sync

WP Remote Users Sync is a WordPress component with 2 published CVE records in this archive. The latest tracked vulnerability was published Aug 16, 2023; the highest CVE/CNA score is 8.5.

Plugin slug: wp-remote-users-sync

CVE-2023-4374: WP Remote Users Sync: A security weakness

WP Remote Users Sync is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedAug 16, 2023
Safe version guidanceSee mitigation notes
Safe version
Aug 16, 2023 CVE-2023-4374
WP Remote Users Sync: A security weakness
WP Remote Users Sync is affected by a security weakness. Exploitation requires an authenticated WordPress account. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Aug 16, 2023 CVE-2023-3958
WP Remote Users Sync: Server-side request forgery
WP Remote Users Sync is affected by server-side request forgery. Exploitation requires an authenticated WordPress account. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE8.5
NVD5.4