Access violation vulnerability in WP-Recall – Registration, Profile, Commerce & More 16.26.10

The WP-Recall plugin for WordPress has a security issue that allows unauthorized users to view data from posts that are supposed to be private or restricted. This vulnerability affects all versions up to 16.26.10 and is caused by a shortcode called ‘feed’ that does not have enough restrictions on what posts can be included. This means that anyone can potentially access sensitive information from password protected, private, or draft posts.

Detected in:

WP-Recall – Registration, Profile, Commerce & More open vulnerable versions: >= * <= 16.26.10

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.