Input validation vulnerability in Easy Form by AYS 1.3.9

The Easy Form by AYS plugin for WordPress is not secure in versions up to 1.3.8. This means that if someone who is not authenticated (not logged in) is able to trick a site administrator into clicking a link, they can make the sale banner disappear. This is because the ays_form_sale_baner() function that is hooked to the “admin_notices” does not have something called a nonce validation.

Detected in:

Easy Form by AYS open vulnerable versions: >= * < 1.3.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.