Input validation vulnerability in BuddyPress Customer.io Analytics Integration 1.1.6

The BuddyPress Customer.io Analytics Integration plugin for WordPress is not secure in versions up to and including 1.1.6. This is because it does not properly protect against malicious requests made by unauthenticated attackers. This means that attackers can trick an administrator into clicking on a link which would allow them to change plugin settings and perform other administrator-level actions.

Detected in:

BuddyPress Customer.io Analytics Integration open vulnerable versions: >= * <= 1.1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.