Access violation vulnerability in WordPress Exit Strategy 1.55

The WordPress Exit Strategy plugin has a security issue that makes it vulnerable to Full Path Disclosure. This means that anyone, even without proper authorization, can access the exitpage.php file and see the full path of the website. This information is not helpful on its own, but can potentially assist in other attacks. The vulnerability exists in all versions of the plugin up to and including 1.55.

Detected in:

WordPress Exit Strategy fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.