Input validation vulnerability in Easy Testimonials 3.7

The Easy Testimonials plugin for WordPress is not secure in versions up to and including 3.6.1. This means that attackers who are not authenticated (not logged in) can alter the information stored by the plugin by sending a link to the site administrator. The link tricks the administrator into performing an action, such as clicking it, which changes the information stored by the plugin. This is due to the missing or incorrect validation of something called nonce on the saveCustomFields() function.

Detected in:

Easy Testimonials open vulnerable versions: >= * < 3.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.