Authentication vulnerability in WP Directorybox Manager 2.5

The WP Directorybox Manager plugin for WordPress has a security issue in versions up to 2.5. This is because the authentication process in the ‘wp_dp_enquiry_agent_contact_form_submit_callback’ function is not working correctly. This could allow hackers who are not logged in to the site to access and use the account of any user, including administrators, if they know the username.

Detected in:

WP Directorybox Manager open vulnerable versions: >= * <= 2.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.