Access violation vulnerability in New User Approve 3.0.9

The New User Approve plugin for WordPress has a security vulnerability that allows unauthorized access to personal information. This can happen in all versions up to 3.0.9 because the API key validation is not strong enough. Attackers who are not logged in can use the Zapier REST API to get usernames and email addresses of users with different approval statuses. This is possible by manipulating the “api_key” parameter to be set as “0” on sites where the Zapier API key has not been set up.

Detected in:

New User Approve fixed vulnerable versions: >= * <= 3.0.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.