Input validation vulnerability in aBitGone CommentSafe 1.0.0

The CommentSafe plugin for WordPress, called aBitGone, has a security flaw that allows for Cross-Site Request Forgery. This vulnerability exists in all versions of the plugin up to and including version 1.0.0. The issue is caused by a problem with the validation of a security measure called a nonce. Because of this flaw, attackers who are not logged in to the site can change the plugin’s settings and insert harmful JavaScript by tricking the site administrator into taking an action, such as clicking on a link.

Detected in:

aBitGone CommentSafe open vulnerable versions: >= * <= 1.0.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.