Access violation vulnerability in Beebee Mini 1.2.0

The Beebee Mini plugin for WordPress contains a security issue with the Advanced Custom Fields feature. This feature allows users to upload files, even if they don’t normally have the permissions to do so. This means that unauthenticated users or users with limited access can upload certain types of files. The upload is handled by WordPress, so the file types and extensions are still checked. However, it is still possible for malicious users with higher privileges to upload dangerous files and bypass other security measures. This security issue affects all versions of the Beebee Mini plugin up to version 1.2.0.

Detected in:

Beebee Mini fixed vulnerable versions: >= * <= 1.2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.