Access violation vulnerability in Instant CSS 1.1.4

The Instant CSS plugin for WordPress is not secure when used in versions up to and including 1.1.4. It is possible for people with access to subscriber-level accounts, and higher, to access and modify data without permission. This data includes CSS, theme, and minify information, as well as changing the options related to these things. It is also possible for attackers to exploit a website using Cross-Site Scripting.

Detected in:

Instant CSS open vulnerable versions: >= * <= 1.1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.