Input validation vulnerability in Revamp CRM for WooCommerce 1.0.4

The Revamp CRM for WooCommerce plugin for WordPress has a security vulnerability in versions up to, and including, 1.0.3. An unauthenticated attacker can use the ‘error_notice’ and ‘success_notice’ parameters to include and execute any file on the server. This can be used to bypass security measures, get access to sensitive data, or even execute code by uploading and including images and other file types that are usually thought of as being safe.

Detected in:

Revamp CRM for WooCommerce open vulnerable versions: >= * < 1.0.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.