Input validation vulnerability in Amazonify 0.8.1

The Amazonify plugin for WordPress, which is used to add Amazon products to a website, has a security flaw in all versions of the plugin up to 0.8.1. This flaw makes it possible for unauthenticated attackers to change the plugin’s settings, including the Amazon Tracking ID, without needing the administrator’s permission. This is possible because the plugin is missing or not properly verifying a security measure called a nonce on the amazonifyOptionsPage() function.

Detected in:

Amazonify open vulnerable versions: >= * <= 0.8.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.