Input validation vulnerability in BNG Gateway For WooCommerce 1.6.10

The BNG Gateway For WooCommerce plugin for WordPress is vulnerable to a security risk known as Cross-Site Request Forgery. This security risk could allow unauthorised attackers to add, edit, or delete payment methods without being logged in. This may happen if the attacker can convince someone with access to the site to click a link. The vulnerability affects versions of the plugin up to and including version 1.6.10, due to incorrect or missing validation of nonce functions.

Detected in:

BNG Gateway For WooCommerce fixed vulnerable versions: >= * <= 1.6.10

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.