Information leakage vulnerability in Felan Framework 1.1.4

The Felan Framework plugin for WordPress has a security issue in versions 1.1.4 and below. This is because the plugin has a hardcoded password in two functions, ‘fb_ajax_login_or_register’ and ‘google_ajax_login_or_register’. This means that someone who is not logged in can access the site as any registered user if they used Facebook or Google to sign up and didn’t change their password.

Detected in:

Felan Framework open vulnerable versions: >= * <= 1.1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.