Input validation vulnerability in Place Order Without Payment for WooCommerce 2.6.7

A plugin called “WC Place Order Without Payment” for the blogging platform WordPress has a security flaw in versions up to 2.6.7. This means that people who are not logged in can access and run any file on the server, including files with PHP code. This can be used to get around security measures, get private information, or run code even if the file type is considered safe.

Detected in:

Place Order Without Payment for WooCommerce fixed vulnerable versions: >= * <= 2.6.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.