Access violation vulnerability in Beyot Framework 6.0.6

Some plugins and themes for WordPress that use Smart Framework are at risk for a certain type of attack called Stored Cross-Site Scripting. This is because they don’t have a safety check in place for two functions called saveOptions() and importThemeOptions(). As a result, attackers who are logged in with a certain level of access can change the plugin’s settings and add harmful code that affects the whole site. Despite being notified two months ago, this issue has not been resolved by Envato.

Detected in:

April Framework open vulnerable versions: >= * <= 5.1
Auteur Framework open vulnerable versions: >= * <= 7.1
Benaa Framework open vulnerable versions: >= * <= 4.0.0
Beyot Framework open vulnerable versions: >= * <= 6.0.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.