Access violation vulnerability in Progress Planner 1.8.0

The Progress Planner plugin for WordPress has a security issue that allows unauthorized changes to be made to the data. This could potentially lead to someone gaining higher privileges. This vulnerability is caused by a missing check in the handle_interactive_task_submit() function in all versions up to and including 1.8.0. Attackers who are logged in with at least Subscriber-level access can exploit this and change certain settings on the WordPress site. This could potentially allow them to change the default role for user registration to administrator and allow them to register as an administrative user, giving them full control over the site.

Detected in:

Progress Planner fixed vulnerable versions: >= * <= 1.8.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.