Input validation vulnerability in Stop Referrer Spam 1.3.0

The Stop Referrer Spam plugin for WordPress is not secure in versions up to and including 1.3.0. This means that people who are not authorized can trick the site administrator into clicking on a link. When this happens, the attacker can refresh the spam blocklist and add their own URLs. The plugin was partially fixed with version 1.3.0, but an empty nonce value can be used to save settings even if the admin page has not been visited.

Detected in:

Stop Referrer Spam open vulnerable versions: >= * <= 1.3.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.