Input validation vulnerability in Locations 3.2.1

The Locations plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This vulnerability affects version 3.2.1 and earlier. The attack is possible because the saveCustomFields() function does not have the correct security measures in place to prevent it. This means if an attacker can get a site administrator to click on a malicious link, they can update the custom field meta data without being logged in.

Detected in:

Locations open vulnerable versions: >= * <= 3.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.