Access violation vulnerability in DX Delete Attached Media 2.0.5.1

The DX Delete Attached Media plugin for WordPress is vulnerable to something called Cross-Site Request Forgery. This means attackers could make changes to the plugin without needing to be authenticated. All versions of the plugin up to and including 2.0.5.1 are vulnerable to this. The problem is caused by the add_to_base function not having the right security measures in place (called nonce validation). If an attacker can get an administrator to click on a link, they could make changes to the plugin’s settings.

Detected in:

DX Delete Attached Media fixed vulnerable versions: >= * <= 2.0.5.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.