Access violation vulnerability in Time Tracker 3.1.0

The Time Tracker plugin for WordPress has a problem that could lead to important information being changed or lost. This is because it doesn’t check for permission when using certain functions. This means that someone who is logged in and has at least Subscriber-level access could make changes to things like user registration and default role. This could allow them to register as an Administrator and delete some information from the database.

Detected in:

Time Tracker fixed vulnerable versions: >= * <= 3.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.