Input validation vulnerability in SEO 4.0.2

The WordPress SEO Wizard plugin, up to version 4.0.2, has a security vulnerability that allows unauthenticated attackers to write data to the .htaccess and robots.txt files without permission. This is possible because of the lack of nonce validation on several functions, which makes it possible to trick a site administrator into taking an action such as clicking on a malicious link.

Detected in:

SEO open vulnerable versions: >= * <= 4.0.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.