Access violation vulnerability in Hestia Nginx Cache 2.4.0

The Hestia Nginx Cache plugin for WordPress has a security issue where unauthorized individuals can access the system without permission. This is because the plugin does not have a necessary check in place to prevent unauthorized users from using the purge() function. This vulnerability exists in versions 2.4.0 and below, allowing attackers who are not logged in to clear the cache.

Detected in:

Hestia Nginx Cache fixed vulnerable versions: >= * <= 2.4.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.