MZ MBO Access
MZ MBO Access has one disclosed vulnerability in the WordSec catalog, all reported in 2021; it is fixed as of September 2026. Their average CVSS score is 8.8, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (100%).
The one issue recorded for MZ MBO Access has a vendor fix available, so running the current release closes it.
All of these findings were reported by WPScanTeam. The current release is tested up to WordPress 5.7.17.
MZ MBO Access <= 2.0.8 - Cross-Site Request Forgery
Read the full analysisVulnerability Records

MZ MBO Access
Author
mikeill
Install and you can limit content based on user MBO memberships: [mbo-client-access access_levels=”1, 2″] RESTRICTED CONTENT HERE [/mbo-client-access] You can also redirect users based on their access level. Until later in 2020, requires access to MBOs v5 (not v6) API. Notes None yet. Hopefully will work well.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C