Input validation vulnerability in Ricerca – advanced search 1.0.15

The Ricerca plugin for WordPress is vulnerable to Cross-Site Request Forgery, a type of attack that can be used to alter the settings of the plugin without requiring authentication from the attacker. This vulnerability affects versions up to and including 1.0.15, as the plugin does not properly validate certain data that is sent when settings are changed. An attacker can exploit this by creating a link or other type of content that can trick a site administrator into clicking on it, which would then change the plugin settings without the admin knowing.

Detected in:

Ricerca – advanced search fixed vulnerable versions: >= * <= 1.0.15

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.