Access violation vulnerability in Omnipress 1.5.4

The Omnipress plugin for WordPress has a security issue that can expose information. This affects all versions up to 1.5.4. The problem is with the megamenu block, which doesn’t have enough restrictions on which posts can be included. This means that people who are logged in and have Contributor-level access or above can access data from posts that are password protected, private, or still in draft form, even though they shouldn’t be able to.

Detected in:

Omnipress open vulnerable versions: >= * <= 1.5.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.