Input validation vulnerability in Ship To eCourier 1.0.1

The Ship To eCourier plugin for WordPress, up to version 1.0.1, has a security vulnerability called Cross-Site Request Forgery. This vulnerability happens because the plugin does not have enough protection to make sure only authorized people can change settings. This means that someone who is not authorized can change settings if they can get an administrator, such as a website owner, to click on a link or do something else.

Detected in:

Ship To eCourier fixed vulnerable versions: >= * <= 1.0.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.