Access violation vulnerability in Swift Framework 2.7.31

The Swift Framework plugin for WordPress has a security issue that allows unauthorized changes to be made to data. This is because the sf_edit_directory_item() function does not have a capability check in versions up to 2.7.31. This means that anyone, without being logged in, can update any post with any content they want. We tried to inform the vendor about this problem, but we did not receive a response.

Detected in:

Swift Framework fixed vulnerable versions: >= * <= 2.7.31

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.