Input validation vulnerability in SRS Simple Hits Counter 1.1.0

The SRS Simple Hits Counter plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This type of attack allows malicious users to modify the plugin’s settings without needing to be authenticated. This is possible because the plugin doesn’t have the right protection in place, which is called a nonce validation. If a malicious user is able to trick an administrator into clicking a link, they can take control of the plugin’s settings. The vulnerability affects all versions up to and including 1.1.0.

Detected in:

SRS Simple Hits Counter open vulnerable versions: >= * <= 1.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.