Input validation vulnerability in Marker.io – Visual Website Feedback 1.1.7

The Marker.io plugin for WordPress has a security vulnerability that could allow an unauthenticated attacker to manipulate the plugin’s settings and save destinations. This vulnerability affects all versions up to and including 1.1.6 and is caused by the lack of nonce validation on the markerio_save_destination() and markerio_save_option() functions. This means that if an attacker can trick a site administrator into performing an action such as clicking on a link, they could perform a Cross-Site Request Forgery.

Detected in:

Marker.io – Visual Website Feedback open vulnerable versions: >= * < 1.1.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.