Input validation vulnerability in MyBookTable Bookstore by Stormhill Media 3.3.3

MyBookTable Bookstore is a plugin for WordPress websites that is currently vulnerable to Cross-Site Request Forgery (CSRF) in versions up to 3.3.3. This means that attackers who are not authorized to access the website can make changes to the API key by tricking the website administrator into clicking on a link or performing another action. This is because the mbt_api_key_refresh_ajax() function does not have proper validation of nonce.

Detected in:

MyBookTable Bookstore by Stormhill Media open vulnerable versions: >= * <= 3.3.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.