Input validation vulnerability in Stamped.io Product Reviews & UGC for WooCommerce 2.3.3

The Stamped.io Product Reviews & UGC for WooCommerce plugin for WordPress has a security vulnerability that could allow unauthenticated attackers to access reviews and clear review caches. This vulnerability exists in versions up to and including 2.3.3. It is caused by missing nonce verification on the clear_reviews_cache function which is accessed via AJAX actions. This vulnerability could be exploited if an attacker is able to create a link that a site administrator clicks on, thus performing an action without realizing it.

Detected in:

Stamped.io Product Reviews & UGC for WooCommerce fixed vulnerable versions: >= * <= 2.3.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.