Access violation vulnerability in Blocksy 2.0.97

The Blocksy theme on WordPress has a security issue that could allow unauthorized access. This is because there is a missing check on the wp_ajax_blocksy_notice_button_click endpoint in versions up to 2.0.97. This means that attackers with administrator-level access or higher could potentially install plugins without permission. However, this would only affect sites where administrators have had their ability to install and activate plugins removed, which could happen on multi-sites.

Detected in:

Blocksy fixed vulnerable versions: >= * <= 2.0.97

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.