Access violation vulnerability in Industrial 1.7.8

The Industrial theme for WordPress has a security issue that allows unauthorized changes to be made to important data, which can result in an increase in privileges. This is because there is no check in place to ensure that only certain users have access to the _ajax_get_total_content_import_items() function. This means that someone with subscriber-level access or higher can make changes to the site’s options, potentially changing the default registration role to administrator and allowing them to register as a user with administrative access.

Detected in:

Industrial fixed vulnerable versions: >= * <= 1.7.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.