Access violation vulnerability in 简数采集器 2.6.3

The plugin called 简数采集器 for WordPress can be easily accessed by hackers to read any file on the server, including sensitive information. This vulnerability exists in all versions up to 2.6.3 and is caused by the __kds_flag feature used to import featured images. Attackers with Adminstrator-level access or higher can exploit this vulnerability.

Detected in:

简数采集器 open vulnerable versions: >= * <= 2.6.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.