Input validation vulnerability in Spicy Blogroll 1.0.0

The Spicy Blogroll plugin is a plugin used for WordPress websites. Unfortunately, versions up to and including 1.0.0 are vulnerable to a type of cyber attack called Local File Inclusion. This type of attack allows unauthenticated attackers to include and execute files on the server, which can be used to bypass access controls, steal sensitive data, or even execute code. This is possible because images and other “safe” file types can be uploaded and included.

Detected in:

Spicy Blogroll open vulnerable versions: >= * <= 1.0.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.