Sandbox <= 0.4 - Missing Authorization to Authenticated (Subscriber+) Sandbox Download

Sandbox <= 0.4 - Missing Authorization to Authenticated (Subscriber+) Sandbox Download

EntreBase Advisory: The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_download action in all versions up to, and including, 0.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to download an entire copy of a sandbox environment which can contain sensitive information like the wp-config.php file.

Read more about this vulnerability: https://www.wordfence.com/threat-intel/vulnerabilities/id/59880d92-5d75-432f-9fb5-d74b13d101ff?source=api-prod

About the Contributor
Trust & Safety
The Trust & Safety team ensures the EntreBase platform remains compliant, safe, and user-friendly. Focused on risk management and user protection, they work to uphold trust and provide a seamless experience.