Input validation vulnerability in WP Custom Post Template 1.0

The WP Custom Post Template plugin for WordPress is vulnerable to malicious attacks in versions up to and including 1.0. An unauthenticated attacker can make changes to the plugin’s settings without permission by tricking an administrator into clicking on a link. This is possible because the plugin is missing an important security feature called nonce validation on the wp_post_template_setting() function.

Detected in:

WP Custom Post Template open vulnerable versions: >= * <= 1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.