Input validation vulnerability in WordPress WP-Advanced-Search 3.3.8

The WP-Advanced-Search plugin for WordPress has a security issue in versions up to 3.3.8. This security issue makes it possible for people who are not authenticated (not logged in) to update certain settings in the plugin. They can do this by tricking a site administrator into clicking on a link. This is because the plugin does not have the right protection (called a nonce) to validate requests.

Detected in:

WordPress WP-Advanced-Search open vulnerable versions: >= * <= 3.3.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.