Access violation vulnerability in Estatik Real Estate Plugin 4.1.0

The Estatik Real Estate Plugin for WordPress has a security vulnerability that allows unauthorized changes to be made to its data. This is because there is no check in place to make sure only certain users have access to the es_dismiss_notices() function. This means that anyone with subscriber-level access or higher can change certain options to “1,” which could potentially cause the plugin to stop working.

Detected in:

Estatik Real Estate Plugin fixed vulnerable versions: >= * <= 4.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.