Input validation vulnerability in which template file 4.6.0

The template file plugin for WordPress is vulnerable to an attack called Cross-Site Request Forgery. This attack can be used by unauthenticated attackers if they can convince a site administrator to click on a link. This type of vulnerability can be found in versions up to and including 4.6.0 of the template file plugin. The reason it is vulnerable to this attack is because it does not have the correct type of validation on one of its functions.

Detected in:

which template file open vulnerable versions: >= * <= 4.8.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.