Access violation vulnerability in Cloudflare 4.12.2

The WordPress plugin called Cloudflare can allow unauthorized users to access data because it doesn’t have a way to check if someone is allowed to use its ‘initProxy’ function. This means that attackers who have an account and some level of access can send requests through Cloudflare to any website they want.

Detected in:

Cloudflare fixed vulnerable versions: >= * <= 4.12.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.