Input validation vulnerability in Client Portal – Private user pages and login 1.1.8

The Client Portal plugin for WordPress is a tool that has a vulnerability in versions 1.1.8 and below. This vulnerability means that an unauthenticated attacker can cause private pages to be created for all users of the website if they can somehow get an administrator of the website to do an action such as clicking on a link. This is possible because the plugin lacks the necessary security checks to stop this from happening.

Detected in:

Client Portal – Private user pages and login fixed vulnerable versions: >= * <= 1.1.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.