Input validation vulnerability in Remove/hide Author, Date, Category Like Entry-Meta 2.1

The Remove/hide Author, Date, Category Like Entry-Meta plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This means that in versions up to 2.1, it is possible for an unauthenticated attacker to update the plugin’s settings without the site administrator’s knowledge, as long as the attacker can get the administrator to click on a link. This is because the plugin does not have the necessary protection to stop this type of attack, known as nonce validation, on the remove_a_d_c() function.

Detected in:

Remove/hide Author, Date, Category Like Entry-Meta open vulnerable versions: >= * <= 2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.