Input validation vulnerability in CRM and Lead Management by vcita 2.6.2

The CRM and Lead Management by vcita plugin for WordPress has a security vulnerability in versions 2.6.2 and earlier. This means that someone without permission could make changes to the plugin’s settings and insert malicious JavaScript into the website if they can trick the site administrator into clicking on a link. To protect against this, the vcita-callback.php file should have something called a nonce validation.

Detected in:

CRM and Lead Management by vcita fixed vulnerable versions: >= * <= 2.7.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.