Access violation vulnerability in Extended Post Status 1.0.19

The Extended Post Status plugin for WordPress has a security issue that could allow someone to change the status of posts without permission. The issue exists in versions up to, and including, 1.0.19. This means that if someone has access to the website with Contributor-level permission or higher, they could change a post from a draft to a ‘published’ post without the website owner’s permission.

Detected in:

Extended Post Status fixed vulnerable versions: >= * <= 1.0.19

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.