PT-2026-95932 · WordPress · Tiktok Plugin For Wordpress
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TikTok WordPress plugin versions prior to 1.4.2
Description
An issue exists where the plugin fails to verify if a request is authorized before processing a sign-in code provided in the URL. This allows any visitor to force the site to redeem a chosen code against the advertising platform using the site's own credentials. The system employs loose matching for the code, meaning URLs that merely resemble the expected format can trigger the process. Additionally, the callback is executed on every request to the site instead of being restricted to the administrator's sign-in process.
Recommendations
Update the TikTok WordPress plugin to version 1.4.2 or later.
Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tiktok Plugin For Wordpress