Input validation vulnerability in Contextual Related Posts 3.3.1

The Contextual Related Posts plugin for WordPress is not secure in versions up to 3.3.1. This plugin is vulnerable to an attack called Cross-Site Request Forgery which can allow unauthorised attackers to clear the Contextual Related Posts cache. This happens when a website administrator clicks on a link sent by the attacker. To protect against this, the crpClearCache function needs to have nonce validation.

Detected in:

Contextual Related Posts fixed vulnerable versions: >= * <= 3.3.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.