Newfold Digital WordPress plugins bundling wp-module-data <=2.9.4 allow unauthenticated attackers to forge a valid Bearer token and gain WordPress administrator access. The authenticate() method (hooked on rest_authentication_errors) computes: token = sha256(sha256(wp_json_encode({method,url,body,timestamp})) + sha256(strrev(get_auth_token()))) On sites not connected to Hiive, get_auth_token() returns false; PHP coerces strrev(false) to strrev('') = '', so the HMAC salt collapses to the public constant sha256('') = e3b0c44... All other inputs are attacker-controlled, enabling offline token forgery without any secret knowledge.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view