Access violation vulnerability in Name Directory 1.25.4

The Name Directory plugin for WordPress is not properly secured in versions up to and including 1.25.4. This means that anyone with a basic user account, such as a subscriber, can make unauthorized changes to the settings of the plugin. These changes can be used to import, edit, and manage directories, and even inject malicious JavaScript into web pages.

Detected in:

Name Directory fixed vulnerable versions: >= * <= 1.25.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.