Input validation vulnerability in yContributors 0.5

The yContributors add-on for WordPress has a security issue called Cross-Site Request Forgery. This affects all versions up to 0.5. The problem is with the ‘yContributors’ page, where there is no proper check to ensure that the request is legitimate. This means that someone who is not logged in can make changes to the settings and insert harmful code into the website by tricking the site administrator into clicking a link.

Detected in:

yContributors open vulnerable versions: >= * <= 0.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.