Input validation vulnerability in Homerunner 1.0.29

The Homerunner plugin for WordPress has a security issue called Cross-Site Request Forgery. This affects all versions up to 1.0.29. The problem is that the main_settings() function does not properly check for a specific code that helps prevent unauthorized changes. Because of this, it is possible for someone without an account to change the plugin’s settings by tricking the site administrator into clicking on a link.

Detected in:

Homerunner fixed vulnerable versions: >= * <= 1.0.30

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.