Input validation vulnerability in WP Crowdfunding 2.1.5

The WP Crowdfunding plugin for WordPress is vulnerable to a type of attack known as Cross-Site Request Forgery. This vulnerability affects all versions of the plugin up to version 2.1.5. This vulnerability occurs because the plugin does not have any measures in place to protect against it, such as nonce validation, on the settings_reset function. This makes it possible for unauthenticated attackers to reset the plugin settings if they can trick a site administrator into clicking on a malicious link.

Detected in:

WP Crowdfunding open vulnerable versions: >= * <= 2.1.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.