Input validation vulnerability in MakeStories (for Google Web Stories) 2.8.0

The MakeStories plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This means that if someone knows how to trick a website administrator into clicking on a link, they can change the settings of the plugin. This vulnerability is present in all versions up to and including 2.8.0 of the plugin. The reason for this is that the “ms_set_options” function is not properly protected against unauthorised access.

Detected in:

MakeStories (for Google Web Stories) open vulnerable versions: >= * <= 3.0.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.