Access violation vulnerability in WP Post Author – The Ideal Author Box for WordPress Posts, Co-Authors and Guest Authors with Author Login and Registration Form Builder 3.2.3

The WP Post Author plugin for WordPress is not properly secured in versions up to 3.2.3. Attackers can use the /set-user-data and /v1/frontend/register-user REST API endpoints to gain access to the website. Once they have access, they can change their role to ‘administrator’, which would give them full control of the site.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.