Access violation vulnerability in Waiting: One-click countdowns 0.6.2

The Waiting plugin for WordPress, which is used to create countdowns, has been found to be vulnerable to authorization bypass in versions up to 0.6.2. This means that anyone with a subscriber-level account or higher can create and delete countdowns, as well as manipulate other plugin settings. This vulnerability can be exploited without any additional action on the part of the user.

Detected in:

Waiting: One-click countdowns open vulnerable versions: >= * <= 0.6.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.