Medium 6.1
2026-05-01< 3.0.7
CVE-2024-13362
Minimum safe version
3.0.7
Update to 3.0.7 or later to address 8 fixable vulnerabilities
CVE-2024-13362
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress Ultimeter Plugin < 2.8.3 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
WordPress Ultimeter plugin < 2.7.6 - Sensitive Information Disclosure vulnerability
WordPress Ultimeter plugin < 2.7.6 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability