Input validation vulnerability in Talkback 1.0

The Talkback plugin for WordPress, up to version 1.0, has a security vulnerability where untrusted information can be used to inject a PHP Object. This can be exploited by attackers who don’t have to log in. There is currently no known way to use this vulnerability to do more harm, but if another plugin or theme is installed on the same system, it could potentially allow the attacker to delete important files, access private information, or run their own code.

Detected in:

Talkback open vulnerable versions: >= * <= 1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.