Input validation vulnerability in Auto Alt Text 2.5.2

The Auto Alt Text plugin used in WordPress has a security vulnerability called Cross-Site Request Forgery. This can affect all versions, including 2.5.2. The issue is caused by not properly checking the identity of the user requesting the action in the handleAltTextBulkAction() function. This means that someone without proper authorization can trick a site administrator into clicking on a link and performing an unauthorized action.

Detected in:

Auto Alt Text fixed vulnerable versions: >= * <= 2.5.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.