Access violation vulnerability in Realty Portal – Agent 0.3.9

The Realty Portal – Agent plugin for WordPress has a security issue that allows hackers to gain higher levels of access without proper authorization. This is because the plugin’s AJAX handler does not have proper restrictions in place when reading and updating user information. As a result, attackers with at least Subscriber-level access can change their own permissions to administrator.

Detected in:

Realty Portal – Agent open vulnerable versions: >= * <= 0.3.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.