Access violation vulnerability in WP Accessibility Helper (WAH) 0.6.2.8

The WP Accessibility Helper (WAH) plugin for WordPress has a security vulnerability that allows unauthorized changes to be made to data. This is because there is no safeguard in place for the ‘save_contrast_variations’ and ‘save_empty_contrast_variations’ functions in all versions up to 0.6.2.8. This means that individuals with at least Subscriber-level access can alter or delete contrast settings. It’s important to note that this issue was fixed in version 0.6.2.8, but the fix caused some problems and the vendor has not addressed our concerns.

Detected in:

WP Accessibility Helper (WAH) fixed vulnerable versions: >= * <= 0.6.2.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.