Access violation vulnerability in Mavix Education 1.0

The Mavix Education theme for WordPress has a security issue that allows people to make changes to the data without permission. This happens because there is no check to see if the user has the right capabilities when using the ‘mavix_education_activate_plugin’ feature. This means that anyone who is logged in and has at least Subscriber-level access can activate the Creativ Demo Importer plugin.

Detected in:

Mavix Education fixed vulnerable versions: >= * <= 1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.