Input validation vulnerability in Finance Consultant – Consulting WordPress Theme 2.8

The Finance Consultant theme for WordPress has a security issue called PHP Object Injection, which can affect versions up to 2.8. This happens when untrusted information is turned into code, making it possible for authorized attackers with subscriber-level permissions or higher to add their own code. There is no known way to exploit this issue, but if there is another plugin or theme installed on the website, it could potentially be used to delete files, access private information, or run code.

Detected in:

Finance Consultant - Consulting WordPress Theme open vulnerable versions: >= * <= 2.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.