Input validation vulnerability in Zajax – Ajax Navigation 0.4

The Zajax – Ajax Navigation plugin for WordPress has a security issue called Cross-Site Request Forgery, which affects all versions up to 0.4. This happens because the plugin does not properly check a specific kind of code. This means that someone who is not logged in could change the plugin’s settings and insert harmful code into the website, as long as they can trick the site’s administrator into taking a certain action, like clicking on a link.

Detected in:

Zajax – Ajax Navigation open vulnerable versions: >= * <= 0.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.