Description
WordPress Plugin WP Private Message is prone to a insecure direct object reference (IDOR) vulnerability. Exploiting this issue may allow an attacker to read arbitrary messages. WordPress Plugin WP Private Message version 1.0.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.0.6 or latest