Access violation vulnerability in The Ultimate WordPress Toolkit – WP Extended 3.0.8

The WP Extended plugin for WordPress has a security vulnerability that could allow unauthorized changes to be made to the data. This could lead to an increase in privileges for the attacker. The issue is caused by a missing capability check in the module_all_toggle_ajax() function in all versions up to and including 3.0.8. This means that attackers with at least Subscriber-level access could change options on the WordPress site, potentially giving them full administrative access. This could be exploited by changing the default role for registration to administrator and enabling user registration, allowing the attacker to gain control of the vulnerable site.

Detected in:

The Ultimate WordPress Toolkit – WP Extended fixed vulnerable versions: >= * <= 3.0.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.