Input validation vulnerability in The World 0.4

The World plugin for WordPress has a security issue called Cross-Site Request Forgery. This means that anyone can make changes to the plugin without being authorized. The problem affects all versions up to 0.4, and it happens because the plugin does not properly check the authorization code. This allows hackers to change settings and add harmful code to a website if they can get a site administrator to click on a link.

Detected in:

The World open vulnerable versions: >= * <= 0.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.