Access violation vulnerability in Melhor Envio 2.11.19

The Melhor Envio plugin for WordPress has a security vulnerability that can be used to change settings without authorization. This vulnerability affects versions up to 2.11.19, which means that any user, authenticated or unauthenticated, can use it to modify the plugin settings. An unauthenticated user will need to get an authenticated user to click on a link in order to exploit it.

Detected in:

Melhor Envio fixed vulnerable versions: >= * <= 2.11.19

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.