Input validation vulnerability in GMAce 1.5.2

The GMAce plugin for WordPress has a security flaw in versions up to 1.5.2 that allows unauthenticated people to modify files on the website and gain access to the system without permission. This is because the plugin does not have a security measure called nonce validation on the gmace_manager_server function called via the wp_ajax_gmace_manager AJAX action which leaves the website vulnerable. This means that if someone can get a website administrator to click on a link

Detected in:

GMAce open vulnerable versions: >= * <= 1.5.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.