Access violation vulnerability in Restrict File Access 1.1.2

The Restrict File Access plugin for WordPress has a security vulnerability that allows attackers to access sensitive information on the server. This can be done by using the output() function and only requires an attacker to have at least Subscriber-level access to the site. This vulnerability exists in all versions of the plugin, up to and including version 1.1.2.

Detected in:

Restrict File Access open vulnerable versions: >= * <= 1.1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.