Input validation vulnerability in Theme My Login 7.1.7

The popular Theme My Login plugin for WordPress is at risk for a type of cyber attack called Cross-Site Request Forgery. This means that hackers can manipulate the plugin’s settings without proper security measures in place. The vulnerability exists in all versions, including the latest one, 7.1.7. Essentially, if an unauthorized person can trick the site administrator into clicking on a link, they can make changes to the plugin’s settings. It’s important to note that this only affects multi-site setups.

Detected in:

Theme My Login fixed vulnerable versions: >= * <= 7.1.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.