Input validation vulnerability in WP-Recall – Registration, Profile, Commerce & More 16.26.14

The WP-Recall plugin for WordPress has a security issue in versions 16.26.14 and below. This means that attackers who have contributor-level access or higher can include and run any files they want on the server, which can contain harmful PHP code. This can be used to get around security measures, access private information, or run code even if the file is considered safe, like images.

Detected in:

WP-Recall – Registration, Profile, Commerce & More open vulnerable versions: >= * <= 16.26.14

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.