Access violation vulnerability in HUMN-1 AI Website Scanner & Human Certification by Winston AI 0.0.3

The HUMN-1 AI Website Scanner & Human Certification by Winston AI plugin for WordPress is at risk of having important information changed without permission. This is because the plugin does not check if a user has the right permission before using the winston_disconnect() function. Anyone with a Subscriber account or higher can use the ‘winston_disconnect’ action to reset the plugin’s API connection settings.

Detected in:

HUMN-1 AI Website Scanner & Human Certification by Winston AI fixed vulnerable versions: >= * <= 0.0.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.