Access violation vulnerability in Frontend Login and Registration Blocks 1.0.7

A plugin called Frontend Login and Registration Blocks for WordPress has a security issue that could allow someone to gain more access than they should. This is because the plugin doesn’t check if a user is who they say they are before letting them change their email address. This means that someone who isn’t even logged in could change the email address of any user, even an administrator. This could then be used to reset the user’s password and get into their account.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.