Input validation vulnerability in Tree Sitemap (Pages, Posts & Categories list) 2.9

The Tree Sitemap plugin for WordPress is vulnerable to a type of cyber attack known as Cross-Site Request Forgery. This type of attack can happen to users who have versions up to and including version 2.9 of the plugin. This is because the plugin is missing a type of security called nonce validation on an AJAX action, which means that unauthenticated attackers can install and activate other plugins on the website if they can get an administrator to click a link or perform some other action.

Detected in:

Tree Sitemap (Pages, Posts & Categories list) fixed vulnerable versions: >= * <= 2.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.