Input validation vulnerability in Block for Font Awesome 1.4.0

The Block for Font Awesome plugin for WordPress has a vulnerability in versions up to and including 1.4.0. Unauthenticated attackers can take advantage of this vulnerability and update the plugin’s settings without needing to be logged in. This is possible if an administrator clicks on a link or performs another action that the attacker has tricked them into doing. To fix this issue, the nonce validation on the getbutterfly_fa_build_admin_page() function must be updated.

Detected in:

Block for Font Awesome fixed vulnerable versions: >= * <= 1.4.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.