Access violation vulnerability in FotaWP 1.4.1

The Fota WP theme for WordPress has a security issue that allows unauthorized changes to be made to the website. This happens because a specific function, called fotawp_install_and_activate_plugins(), does not have a proper check to ensure only authorized users can use it. This vulnerability exists in versions 1.4.1 and earlier, and can be exploited by attackers who are not logged in to the website.

Detected in:

FotaWP fixed vulnerable versions: >= * <= 1.4.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.