Access violation vulnerability in Post Meta Data Manager 1.2.0

The Post Meta Data Manager plugin for WordPress is vulnerable to changes being made and data being lost without permission. This is because there are missing security checks for the pmdm_wp_ajax_delete_meta, pmdm_wp_delete_user_meta, and pmdm_wp_delete_user_meta functions which are hooked onto AJAX actions in all versions up to 1.2.0. This means that an attacker who is not authenticated could delete any user, term, and post meta they wanted to.

Detected in:

Post Meta Data Manager open vulnerable versions: >= * <= 1.2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.