Medium 6.3
2024-10-16< 1.2.7
Freemius SDK <= 2.4.2 - Missing Authorization Checks
Minimum safe version
1.2.8
Update to 1.2.8 or later to address 6 fixable vulnerabilities
Freemius SDK <= 2.4.2 - Missing Authorization Checks
CVE-2024-44020
WordPress WP Free SSL – Free SSL Certificate for WordPress and force HTTPS Plugin < 1.2.6 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.4.2 - Missing Authorization Checks
WordPress WP Free SSL – Free SSL Certificate for WordPress and force HTTPS plugin < 1.2.7 - Sensitive Information Disclosure vulnerability
WordPress WP Free SSL – Free SSL Certificate for WordPress and force HTTPS plugin < 1.2.7 - Toggle The Debug Mode via Cross-Site Request Forgery (CSRF) vulnerability