Input validation vulnerability in RateMyAgent Official 1.4.0

The RateMyAgent Official plugin for WordPress has a security issue called Cross-Site Request Forgery. This can happen in all versions up to 1.4.0. The problem is that the ‘rma-settings-wizard’ is missing or has incorrect validation for nonces. This means that people who are not logged in can change the plugin’s API key if they can trick the site administrator into doing something, like clicking on a link.

Detected in:

RateMyAgent Official fixed vulnerable versions: >= * <= 1.4.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.