Input validation vulnerability in Stock Sync for WooCommerce 2.3.2

The Stock Sync for WooCommerce plugin for WordPress is vulnerable to a type of attack known as Cross-Site Request Forgery up to version 2.3.2. This means that attackers can send a forged request to the website which may trick an administrator into clicking on a link. This can lead to stock quantities being pushed to external sites or log tables being created without the administrator’s authorization due to missing or incorrect nonce validation on the function push_all, push, update, create_log_table.

Detected in:

Stock Sync for WooCommerce fixed vulnerable versions: >= * <= 2.3.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.