Input validation vulnerability in Duplicate Theme 0.1.6

The Duplicate Theme plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This vulnerability affects all versions of the plugin up to version 0.1.6. It is caused by the themeDuplicationAction function not having the right kind of security measures in place, meaning it can be tricked into allowing unauthenticated attackers to duplicate themes. This could happen if a site administrator is tricked into clicking on a malicious link.

Detected in:

Duplicate Theme open vulnerable versions: >= * <= 0.1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.