Access violation vulnerability in WHMCS Client Area for WordPress by WHMpress 4.3-revision-3

The WHMPress plugin for WordPress has a security vulnerability that could allow unauthorized changes to be made to data. This could lead to an increase in privileges for attackers, as there is no check in place to ensure the proper permissions are granted. This vulnerability exists in all versions up to and including 4.3-revision-3. This means that attackers who are authenticated and have at least Subscriber-level access can update any options on the WordPress site. This could potentially be used to change the default role for registration to administrator, giving attackers access to administrative privileges on a vulnerable site.

Detected in:

WHMCS Client Area for WordPress by WHMpress open vulnerable versions: >= * <= 4.3-revision-3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.