Input validation vulnerability in Grab & Save 1.0.4

The Grab & Save plugin for WordPress is vulnerable to a type of cyber attack called Cross-Site Request Forgery in versions up to 1.0.4. This is because the plugin did not properly validate a security feature known as a “nonce”, which helps protect websites from malicious attacks. This vulnerability makes it possible for unauthenticated attackers to upload images without the site administrator’s knowledge, as long as they can trick the administrator into clicking on a link.

Detected in:

Grab & Save open vulnerable versions: >= * <= 1.0.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.