Input validation vulnerability in Top 10 – Popular posts plugin for WordPress 2.9.5

The Top 10 plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This affects versions up to and including 2.10.4. This means that if someone can get a site administrator to click a link, they can use this vulnerability to get access to the top 10 table without having to be authenticated. This happens because the plugin does not have the right kind of protection (called nonce validation) on the tptn_export_tables() function.

Detected in:

Top 10 – Popular posts plugin for WordPress fixed vulnerable versions: >= * < 2.9.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.