Access violation vulnerability in Configurator Theme Core 1.4.7

The Configurator Theme Core plugin for WordPress has a security issue that allows users to gain higher levels of access than they should have. This problem affects all versions of the plugin, including version 1.4.7. The issue is caused by the plugin not checking user information carefully before making changes to the database. As a result, attackers who are logged in and have at least Subscriber-level access can increase their privileges to the level of Administrator.

Detected in:

Configurator Theme Core open vulnerable versions: >= * <= 1.4.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.