Access violation vulnerability in Booster Elementor Addons 1.4.9

The Booster Elementor Addons plugin for WordPress has a security vulnerability that could allow someone who is not authorized to access and change data on the website. This vulnerability affects versions up to and including 1.4.9 and is due to the missing permission checks on certain functions that are available via the AJAX actions in the ~/base/core/ajax_handler.php file. This means an unauthorized person could carry out a variety of activities such as loading the icon chooser and saving active widgets and extensions.

Detected in:

Booster Elementor Addons open vulnerable versions: >= * <= 1.4.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.