Input validation vulnerability in immonex Kickstart Team 1.6.9

A popular plugin for WordPress called immonex Kickstart Team has a security flaw in versions 1.6.9 and below. This flaw allows attackers with contributor-level access or higher to include and run any files they want on the server. This means they can run malicious code and access sensitive information. Even files that are usually considered safe, like images, can be used to execute this attack.

Detected in:

immonex Kickstart Team fixed vulnerable versions: >= * <= 1.6.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.