Input validation vulnerability in WP User Groups 2.1.0

The WP User Groups plugin for WordPress has a security issue in versions up to 2.1.0. An attacker who can get a site administrator to click a link could use it to do restricted actions like putting users into groups without needing to authenticate first. This is because the plugin doesn’t have the right security measures in place, like validation of nonce, on the save_terms_for_user and handle_bulk_actions functions.

Detected in:

WP User Groups fixed vulnerable versions: >= * <= 2.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.