Input validation vulnerability in Xews Lite 1.0.9

The Xews Lite theme for WordPress has a security issue called “Local File Inclusion” in versions 1.0.9 and below. This means that people who are not logged in can access and run any files on the server, even if they contain harmful code. This can lead to getting around security measures, accessing private information, or running code when seemingly safe files like images are uploaded and used.

Detected in:

Xews Lite fixed vulnerable versions: >= * <= 1.0.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.