Input validation vulnerability in MemorialDay 1.0.4

The MemorialDay plugin for WordPress has a security issue called Cross-Site Request Forgery. This can affect all versions up to 1.0.4. The problem is that there is not enough protection in place to prevent unauthorized changes to the settings. This means that someone who is not logged in can make changes and add harmful code to a website by tricking the site administrator into clicking on a link.

Detected in:

MemorialDay fixed vulnerable versions: >= * <= 1.0.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.