Access violation vulnerability in WP-MUI – Mass User Input – Add and Export WP Users Quickly 1.8

The WP-MUI plugin for WordPress is vulnerable to authorization bypass in versions up to 1.8. This means that attackers with user permissions of at least ‘subscriber’ level can perform actions that they are not authorized for. This vulnerability is due to missing capability checks in the ~/core/ajax_handler.php file.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.