Input validation vulnerability in Voting Record 2.0

The Voting Record plugin for WordPress has a security issue called Cross-Site Request Forgery. This problem affects all versions up to and including 2.0. It happens because a certain security measure is missing or not working correctly. This means that people who are not logged in can change the plugin’s settings and add code to the site if they can trick the person in charge of the site into doing something, like clicking on a link. It’s not clear how serious this problem is.

Detected in:

Voting Record open vulnerable versions: >= * <= 2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.