Access violation vulnerability in WP01 – Speed, Security, SEO consultant 2.6.2

The WP01 plugin used in WordPress has a security issue that allows anyone with Subscriber-level access or higher to download and view files on the server. This is because there is no check to see if the user has the right permissions and the make_archive() function is not restricted enough. This means that sensitive information could be accessed by malicious individuals.

Detected in:

WP01 – Speed, Security, SEO consultant open vulnerable versions: >= * <= 2.6.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.