Input validation vulnerability in Kebo Twitter Feed 1.5.12

The Kebo Twitter Feed WordPress plugin is vulnerable to a type of cyber attack known as Cross-Site Request Forgery. Versions up to and including 1.5.12 of the plugin are affected. This is because the plugin does not include the correct protection against this type of attack, known as a ‘nonce validation’, on one of its functions. This means that if a malicious actor is able to trick an administrator into clicking on a link, it could be possible for the actor to change the plugin settings without being properly authenticated.

Detected in:

Kebo Twitter Feed open vulnerable versions: >= * <= 1.5.12

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.