Authentication vulnerability in CE21 Suite 2.3.1

The CE21 Suite plugin for WordPress can be hacked by people who are not authorized to change its settings. This is because the plugin does not check if the person trying to change the settings has the right permissions. This means that anyone can change the plugin’s settings, including a secret key that is used to make sure the person changing the settings is allowed to do so. This could allow someone to create new admin accounts on a website that is using this plugin.

Detected in:

CE21 Suite open vulnerable versions: >= 2.2.1 <= 2.3.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.