Access violation vulnerability in Upload.am – File Hosting & VPN 1.0.0

The Upload.am plugin for WordPress has a vulnerability that allows unauthorized access to data. This is because it does not properly check for permissions on the ‘upload_am_get_option’ feature. This issue exists in all versions up to and including 1.0.0. This means that attackers who are logged in and have Contributor or higher level access can access any option values.

Detected in:

Upload.am – File Hosting & VPN fixed vulnerable versions: >= * <= 1.0.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.