Input validation vulnerability in Erident Custom Login and Dashboard 3.4.1

The Erident Custom Login & Dashboard plugin for WordPress is a software program that is vulnerable to exploitation in versions 3.4.1 and below. This means that a third-party can potentially access and modify the settings of the plugin without the permission of the site administrator. This can be done by sending a malicious link to the administrator and hoping they click on it. Unfortunately, this is made possible because the security measures, called ‘nonce validation’, are missing or not properly implemented in the file ‘erident-custom-login-and-dashboard/trunk/er-custom-login.php’.

Detected in:

Erident Custom Login and Dashboard fixed vulnerable versions: >= * <= 3.4.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.