Access violation vulnerability in Opal Membership 1.2.4

The Opal Membership plugin for WordPress has a security issue that can expose sensitive information. This affects all versions up to and including 1.2.4. The problem is with the private notes feature on payments, which uses WordPress comments. This means that even users with subscriber-level access or higher can see private notes through recent comments, even though only administrators should have access to them.

Detected in:

Opal Membership open vulnerable versions: >= * <= 1.2.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.