Input validation vulnerability in WP w3all phpBB 2.9.3

The WP w3all phpBB plugin for WordPress has a security issue called Cross-Site Request Forgery. This problem affects all versions up to 2.9.3. The issue occurs because a function does not properly check for a special code that verifies the user’s identity. This allows attackers who are not logged in to the site to perform actions that they should not be able to do. They can do this by tricking the site administrator into clicking on a link.

Detected in:

WP w3all phpBB fixed vulnerable versions: >= * <= 2.9.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.