Input validation vulnerability in uContext for Amazon 3.9.1

The uContext for Amazon plugin for WordPress is not secure in versions up to and including 3.9.1. It can be exploited by unauthenticated attackers in a way that allows them to change the plugin’s settings and add malicious web scripts. This is possible because the ~/app/sites/ajax/actions/keyword_save.php file does not use a security measure called nonce validation

Detected in:

uContext for Amazon open vulnerable versions: >= * <= 3.9.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.