Input validation vulnerability in Apollo13 Framework Extensions 1.9.1

The Apollo13 Framework Extensions plugin for WordPress is not secure in versions up to 1.9.1. This means that if a malicious person can find a way to trick a site administrator, like getting them to click on a link, they can add and delete posts from the website without being authenticated. This is because the plugin does not have the right kind of security protection called nonce validation on the a13fe_nava_add_post and a13fe_nava_delete_post functions.

Detected in:

Apollo13 Framework Extensions fixed vulnerable versions: >= * <= 1.9.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.