Input validation vulnerability in HotStar – MultiPurpose Business WordPress Theme 1.4

A popular WordPress theme called HotStar, which can be used for various types of businesses, has a security issue where untrusted input can be used to inject a PHP Object. This can be exploited by attackers who don’t need to be authenticated, meaning they don’t need a username or password. There is no known way to protect against this issue, but if another plugin or theme is also installed on the website, it could potentially make the situation worse by allowing the attacker to delete files, access private information, or run their own code on the website.

Detected in:

HotStar – MultiPurpose Business WordPress Theme open vulnerable versions: >= * <= 1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.