Input validation vulnerability in WP Finance 1.3.6

The WP Finance plugin for WordPress has a security flaw that can be exploited by anyone, even those who are not authorized to access the website. This vulnerability is present in all versions, up to 1.3.6. The issue lies in the lack of proper security checks on the ‘wpfinance’ page, allowing attackers to manipulate settings and insert harmful code into the site. They can do this by tricking a site administrator into taking a certain action, such as clicking on a link.

Detected in:

WP Finance open vulnerable versions: >= * <= 1.3.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.