Input validation vulnerability in Buying Buddy IDX CRM 1.1.12

The Buying Buddy IDX CRM plugin for WordPress, up to version 1.1.12, has a security issue called Cross-Site Request Forgery. This is because it doesn’t properly check for a special code when carrying out one of its functions. This means that hackers who are not logged in can add their own code and make it do certain things, as long as they can trick an administrator into doing something like clicking on a link.

Detected in:

Buying Buddy IDX CRM fixed vulnerable versions: >= * <= 1.2.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.