Input validation vulnerability in Leadinfo 1.0

The Leadinfo plugin for WordPress has a security issue called Cross-Site Request Forgery. This affects all versions up to version 1.0. The problem is that there is no proper check to make sure that only authorized users are making requests. This means that someone without an account can trick a website administrator into doing something without their knowledge. The extent of the damage caused by this vulnerability is not known.

Detected in:

Leadinfo fixed vulnerable versions: >= * <= 1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.