Access violation vulnerability in Portfolio and Projects 1.3.7

The Portfolio and Projects plugin for WordPress has a security vulnerability in versions up to and including 1.3.7. Attackers can potentially take advantage of this vulnerability by tricking a site administrator into clicking on a malicious link. This would allow the attackers to dismiss any notices on the website without the administrator’s permission. To protect against this, the plugin must have the correct nonce validation on the ‘wpos_anylc_admin_init_process’ function.

Detected in:

Portfolio and Projects fixed vulnerable versions: >= * <= 1.3.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.