Input validation vulnerability in WPPerformanceTester 2.0.0

The WPPerformanceTester plugin for WordPress has a security flaw in versions 2.0.0 and lower. This flaw allows attackers to make requests to the website without being authenticated (logged in). They can do this by making a link that tricks the site administrator into clicking on it, and then the attacker can take some action on the website without permission. To protect against this, the plugin should be updated to include protection against forged requests.

Detected in:

WPPerformanceTester open vulnerable versions: >= * <= 2.0.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.