Input validation vulnerability in Q and A 1.0.6.2

The Q and A plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This plugin is affected if it is using versions 1.0.6.2 or earlier. The problem is that the security measures that are meant to protect the plugin, called “nonce validation”, do not work properly. This means that people who are not authorized to access the plugin can potentially use it to perform malicious actions, such as running malicious code or accessing data they’re not supposed to. These types of attacks are explained in more detail in a reference.

Detected in:

Q and A open vulnerable versions: >= * <= 1.0.6.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.