Access violation vulnerability in Agency Toolkit 1.0.23

The Agency Toolkit plugin for WordPress has a security issue that allows unauthorized changes to be made to its data. This can lead to a higher level of access being granted, even to unauthenticated attackers. The problem is due to a missing capability check on the ‘agency_toolkit_import’ action in all versions up to 1.0.23. This means that anyone can update certain settings on a WordPress site without being logged in. This could potentially give attackers the ability to change the default registration role to administrator and allow them to create new user accounts with administrative access.

Detected in:

Agency Toolkit fixed vulnerable versions: >= * <= 1.0.23

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.