Input validation vulnerability in GravatarLocalCache 1.1.2

The GravatarLocalCache plugin for WordPress has a security issue that makes it vulnerable to a type of attack called Cross-Site Request Forgery. This can happen in any version of the plugin up to version 1.1.2. The problem is caused by a missing or incorrect security check that normally prevents unauthorized changes to the plugin’s settings. This means that someone who is not logged in to the website could potentially change the settings and add harmful code to the website, as long as they can trick the site administrator into doing something like clicking on a link.

Detected in:

GravatarLocalCache open vulnerable versions: >= * <= 1.1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.