Access violation vulnerability in Croma Music 3.6

The Croma Music plugin for WordPress has a security issue that allows unauthorized changes to be made to the data. This can lead to someone with limited access being able to gain higher privileges and potentially take control of the website. The problem lies in the ‘ironMusic_ajax’ function in all versions up to 3.6, which does not properly check for permissions. This means that someone with at least Subscriber-level access can change important settings on the website, including making themselves an administrator and allowing others to register as users.

Detected in:

Croma Music fixed vulnerable versions: >= * <= 3.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.