Input validation vulnerability in Himer 2.1.0

The Himer theme for WordPress has a security vulnerability called Cross-Site Request Forgery. This vulnerability affects all versions up to version 2.1.0. The problem is that there is no proper check to make sure that the request is valid when using the wpqa_join_group feature. This means that someone who is not logged in can trick a site administrator into taking an action, like clicking on a link, and then join a private group without permission.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.