The Spice Starter Sites plugin for WordPress can be changed by anyone without permission because it doesn’t have a check to make sure they have the right abilities. This means that people who aren’t logged in can add demo content to the site.
Documentation: Home / Vulnerabilities / Access violation vulnerability in Spice Starter Sites 1.2.5
The Spice Starter Sites plugin for WordPress can be changed by anyone without permission because it doesn’t have a check to make sure they have the right abilities. This means that people who aren’t logged in can add demo content to the site.
This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!
Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:
> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21
Is this information incorrect? Please leave us a message.
© Really Simple Plugins
CoC 70461155
Kalmarweg 14-5
9723 JG, Groningen (NL)