Access violation vulnerability in CozyStay – Hotel Booking WordPress Theme 1.7.0

The CozyStay theme for WordPress has a security issue that could allow unauthorized people to change data without permission. This is because the theme does not check for certain capabilities when using the ajax_handler function. This vulnerability exists in all versions of the theme up to version 1.7.0, which means that attackers who are not logged in could potentially carry out harmful actions.

Detected in:

CozyStay - Hotel Booking WordPress Theme fixed vulnerable versions: >= * <= 1.7.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.