Access violation vulnerability in WP User Manager – User Profile Builder & Membership 2.9.11

The WP User Manager plugin for WordPress is at risk for having its data changed without permission. This is because it doesn’t check for the proper permissions when using the ‘add_sidebar’ and ‘remove_sidebar’ functions. This means that anyone who has at least Subscriber-level access can make changes to a custom sidebar made with the Carbon Fields plugin, if it is also installed.

Detected in:

WP User Manager – User Profile Builder & Membership fixed vulnerable versions: >= * <= 2.9.11

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.