Input validation vulnerability in CheckBot 1.05

The CheckBot plugin for WordPress has a security issue called Cross-Site Request Forgery. This affects all versions, including 1.05. The problem is that the plugin doesn’t properly check for a special code that helps prevent unauthorized changes. This means that someone who isn’t logged in could change settings and add harmful code to the website by tricking the site’s administrator into clicking a link.

Detected in:

CheckBot open vulnerable versions: >= * <= 1.05

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.