Input validation vulnerability in Unlimited Category slider for WooCommerce 2.0.0

The Unlimited Category Slider for WooCommerce plugin for WordPress is vulnerable to a security issue in versions up to and including 2.0.0. This issue makes it possible for unauthenticated attackers to gain access to administrative actions that they would not normally be able to access. This is because the plugin is missing or has incorrect validation on the “cx_nonce” function. An attacker could exploit this issue by tricking a site administrator into performing an action such as clicking on a link.

Detected in:

Category slider for WooCommerce fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.