Access violation vulnerability in Connector to CiviCRM with CiviMcRestFace 1.0.9

The way that the Connector to CiviCRM works with the CiviMcRestFace plugin for WordPress has a security issue. This means that anyone can access it without permission, because there is a function that doesn’t check if the person has the right capabilities. This can allow people who are not signed in to do things they shouldn’t be allowed to do.

Detected in:

Connector to CiviCRM with CiviMcRestFace fixed vulnerable versions: >= * <= 1.0.10

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.