Access violation vulnerability in Droip 2.2.0

The Droip plugin for WordPress has a security issue that allows unauthorized changes and access to data. This is because the plugin does not check for the proper permissions when using the droip_post_apis() function. This means that attackers who are logged in with at least Subscriber-level access can perform various actions through the plugin’s AJAX hooks. This could result in things like deleting posts, creating new posts, copying posts, changing settings, manipulating user accounts, and more.

Detected in:

Droip open vulnerable versions: >= * <= 2.2.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.