Access violation vulnerability in AI Hub – Startup & Technology WordPress Theme *

Several plugins and/or themes created by LiquidThemes for WordPress are prone to unauthorized access. This is because they do not have a proper check in place for the liquid_reset_wordpress_before AJAX in different versions. As a result, attackers with at least Subscriber-level access can deactivate all plugins on a website. We reported this issue to Envato, but after failing to make contact, the developer added a nonce check. However, this is not enough protection as the nonce can still be seen by all users with dashboard access.

Detected in:

AI Hub - Startup & Technology WordPress Theme fixed vulnerable versions: >= * <= *
ArcHub - Architecture and Interior Design WordPress Theme fixed vulnerable versions: >= * <= *
Hub - Responsive Multi-Purpose WordPress Theme fixed vulnerable versions: >= * <= *

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.