Input validation vulnerability in Smart App Banner 1.1.3

The Smart App Banner plugin for WordPress is vulnerable to a type of cyber attack called Cross-Site Request Forgery. This affects versions up to 1.1.2 of the plugin. The problem is caused by missing or incorrect security measures (known as nonce validation) when changing the plugin’s settings. This means that if a malicious user can get a website administrator to do something (such as clicking a link), they can change the plugin’s settings without authentication.

Detected in:

Smart App Banner fixed vulnerable versions: >= * < 1.1.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.