Input validation vulnerability in bbPress2 shortcode whitelist 2.2.1

The bbPress2 shortcode whitelist plugin used in WordPress has a security issue called Cross-Site Request Forgery. This can be found in all versions up to 2.2.1. The problem is caused by the lack of proper checks on a certain function. This means that people who are not logged in can make changes to the plugin settings and insert harmful code onto the website, as long as they can trick the site administrator into doing something like clicking on a link.

Detected in:

bbPress2 shortcode whitelist fixed vulnerable versions: >= * <= 2.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.