Input validation vulnerability in CMS Commander – Manage Multiple Sites 2.287

The WordPress CMS Commander plugin has a security flaw that could let unauthorised people gain access to it. This is due to the fact that the plugin uses a unique code which is not secure enough. This code can be changed, allowing the plugin to be controlled remotely with commands such as creating an administrator access URL. This could be used to gain higher levels of access and cause serious damage. To be vulnerable, the plugin must not be configured yet, but if used alongside other security flaws, the impact can be severe.

Detected in:

CMS Commander – Manage Multiple Sites fixed vulnerable versions: >= * <= 2.287

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.