Input validation vulnerability in Floating Action Button 1.2.1

The Floating Action Button plugin for WordPress is vulnerable to a security issue called Cross-Site Request Forgery. This vulnerability affects versions up to and including 1.2.1. This issue occurs because a function in the plugin does not have the correct security measures (known as nonce validation) to protect it. This means that someone who is not authorized to use the plugin could possibly make a special type of request (called a forged request) that a website administrator could unknowingly click on and perform an action.

Detected in:

Floating Action Button open vulnerable versions: >= * <= 1.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.