Input validation vulnerability in Add to Cart Text Changer and Customize Button, Add Custom Icon 2.0

The Add to Cart Text Changer and Customize Button, Add Custom Icon plugin for WordPress has an issue in versions up to, and including, 2.0 that leaves it vulnerable to Cross-Site Request Forgery. This means that if an attacker can trick a site administrator into clicking on a link, they can make changes to the WooCommerce Add to Cart text without authentication due to a lack of proper nonce validation on the wactc_text_form function.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.