Access violation vulnerability in WP Directory Kit 1.2.3

The WP Directory Kit plugin for WordPress is not secure in versions up to 1.2.3, as it does not properly check if someone is allowed to make changes. This means that someone with user permissions of at least a subscriber could delete or change plugin settings, import demo data, delete Directory Kit related posts and terms, and install arbitrary plugins. A partial patch was introduced in version 1.2.0 to address this issue.

Detected in:

WP Directory Kit open vulnerable versions: >= * <= 1.2.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.