Input validation vulnerability in Replyable – Subscribe to Comments and Reply by Email 2.2.9

The Replyable plugin for WordPress is vulnerable to security issues in versions up to and including 2.2.9. If an unauthenticated attacker is able to trick a site administrator into clicking a link, they can use Cross-Site Request Forgery and PHP Object Injection to inject a malicious code on the site. If there is a useable gadget installed, it could potentially lead to a remote code execution.

Detected in:

Replyable – Subscribe to Comments and Reply by Email open vulnerable versions: > 0 < 0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.