Input validation vulnerability in WP Reactions Lite 1.3.8

The WP Reactions Lite plugin for WordPress is vulnerable to a type of attack known as Cross-Site Request Forgery in versions up to and including 1.3.8. This type of attack occurs because the plugin is missing or has incorrect validation on several AJAX actions. This makes it possible for unauthenticated attackers to make a forged request and trick a site administrator into clicking a link or performing some other action.

Detected in:

WP Reactions Lite fixed vulnerable versions: >= * <= 1.3.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.