Access violation vulnerability in Buy Me a Coffee – Button and Widget Plugin 3.7

The Buy Me a Coffee – Button and Widget Plugin for WordPress is vulnerable to data manipulation without authorization in versions up to 3.7. This means that even people with limited access to the website, such as subscribers, can modify the plugin settings. It is possible that this issue may be the same as CVE-2023-25030.

Detected in:

Buy Me a Coffee – Button and Widget Plugin open vulnerable versions: >= * <= 3.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.