Access violation vulnerability in License Manager for WooCommerce 3.0.7

A plugin called “License Manager for WooCommerce” on WordPress has a security issue that allows unauthorized access to data. This is because it does not check for the proper permissions when using the showLicenseKey() and showAllLicenseKeys() functions, in versions up to 3.0.7. This means that someone who is logged in as an admin (or contributor) can see decrypted license keys without permission. The plugin does have a security measure in place, but it can be bypassed through a “license” variable in the dashboard.

Detected in:

License Manager for WooCommerce open vulnerable versions: >= * <= 3.0.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.