Input validation vulnerability in DrawBlog 0.81

The DrawBlog plugin for WordPress is vulnerable to a type of cyber attack called Cross-Site Request Forgery in versions before 0.81. This type of attack does not require the attacker to sign in or authenticate in any way. Instead, they can trick a site administrator into performing an action, such as clicking a link, which will allow the attacker to change the settings of the DrawBlog plugin. This happens because the plugin does not have the necessary security measures in place to prevent this type of attack.

Detected in:

DrawBlog open vulnerable versions: >= * < 0.81

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.