Authentication vulnerability in Mesmerize 1.6.89

The Mesmerize and Materialis themes for WordPress have a security vulnerability in versions 1.6.89 (Mesmerize) and 1.0.172 (Materialis) and earlier. This vulnerability allows anyone who is logged in to the WordPress site to change certain options that should normally be restricted. This is because the function designed to stop this from happening, ‘companion_disable_popup’, only checks the nonce when sending user input to the ‘update_option’ function.

Detected in:

Materialis fixed vulnerable versions: >= * <= 1.0.172
Mesmerize fixed vulnerable versions: >= * <= 1.6.89

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.