Access violation vulnerability in All Users Messenger 1.24

The All Users Messenger plugin for WordPress is a plugin that is vulnerable to a security issue. This security issue is called an Insecure Direct Object Reference and affects versions of the plugin up to and including version 1.24. This security issue occurs because the plugin does not check for valid information when a user is trying to access certain features. This means that someone who is logged in with a subscriber account could delete messages that they are not supposed to be able to delete.

Detected in:

All Users Messenger open vulnerable versions: >= * <= 1.24

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.