Input validation vulnerability in UltraPress 1.2.1

The UltraPress theme for WordPress has a security issue called PHP Object Injection. This can happen in all versions up to 1.2.1 when untrusted input is used. It lets attackers who are logged in with Contributor-level or higher access inject a PHP Object. There is no known way to protect against this in the vulnerable software. However, if there is a way through an extra plugin or theme on the system, the attacker could delete files, get important information, or run code.

Detected in:

UltraPress open vulnerable versions: >= * <= 1.2.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.