Input validation vulnerability in Simple Documentation 1.2.8

The Simple Documentation plugin for WordPress has a security issue called Cross-Site Request Forgery in versions 1.2.8 and below. This is because there is a problem with how the plugin checks for a specific code (nonce) when performing a certain function. This means that someone who is not logged in to the website could change settings and insert harmful code into the site by tricking the person in charge (site administrator) into clicking on a link.

Detected in:

Simple Documentation open vulnerable versions: >= * <= 1.2.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.