Access violation vulnerability in WPC Smart Messages for WooCommerce 4.2.1

The WPC Smart Messages for WooCommerce plugin on WordPress is at risk for unauthorized activation or deactivation of Smart Messages. This is because the function for ajax_enable does not have a check for capabilities, in versions up to 4.2.1. This means that attackers who are logged in with Subscriber-level access or higher can turn on or off smart messages without permission.

Detected in:

WPC Smart Messages for WooCommerce open vulnerable versions: >= * <= 4.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.