Authentication vulnerability in Sala – Startup & SaaS WordPress Theme 1.1.4

The Sala – Startup & SaaS WordPress Theme for WordPress has a security issue that can allow someone to access and take control of user accounts. This problem affects all versions of the theme up to and including 1.1.4. The issue is caused by the theme not properly checking a user’s identity before allowing them to change their password. This means that even someone without an account can potentially change the password of any user, including administrators, and use that to gain unauthorized access to their account.

Detected in:

Sala - Startup & SaaS WordPress Theme fixed vulnerable versions: >= * <= 1.1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.