Input validation vulnerability in Quantity Plus Minus Button for WooCommerce by CodeAstrology 1.1.9

The Quantity Plus Minus Button for WooCommerce by CodeAstrology plugin for WordPress is vulnerable to a type of cyber attack called Cross-Site Request Forgery. This is because the plugin doesn’t have enough security to make sure only users that are logged in can make changes to the plugin. This means that someone who is not logged in could make changes to the plugin’s settings if they can get an administrator to click on a link or do something else. This affects versions up to and including 1.1.9.

Detected in:

Quantity Plus Minus Button for WooCommerce fixed vulnerable versions:
Quantity Plus Minus Button for WooCommerce by CodeAstrology fixed vulnerable versions: >= * <= 1.1.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.