Access violation vulnerability in WP Discourse 2.5.9

The WP Discourse plugin for WordPress has a security issue that could allow sensitive information to be exposed. This can happen in all versions of the plugin up to version 2.5.9. The problem is that the plugin sends important credentials to any website mentioned in a post’s custom field, making it possible for hackers with certain levels of access to steal this information and potentially launch more attacks.

Detected in:

WP Discourse fixed vulnerable versions: >= * <= 2.5.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.