Input validation vulnerability in FULL – Cliente 3.1.25

The Customer plugin for WordPress has a security issue in versions up to 3.1.25. This means that people who are logged in and have contributor-level access or higher can access and run any files they want on the server. This can lead to bypassing security measures, getting confidential information, or running code even if only “safe” files like images are allowed to be uploaded.

Detected in:

FULL – Cliente fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.