Access violation vulnerability in UiPress lite | Effortless custom dashboards, admin themes and pages 3.5.08

The UiPress lite plugin for WordPress, which allows for easy customization of dashboards, admin themes, and pages, can be manipulated by unauthorized users. This is because the plugin does not check for the proper permissions before making changes to data. This vulnerability exists in all versions up to and including 3.5.08. As a result, attackers who have at least Subscriber-level access can modify plugin settings and other AJAX actions.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.