Input validation vulnerability in Events Addon for Elementor 2.1.2

The Events Addon for Elementor plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery in all versions up to 2.1.2. This type of attack can be used by unauthenticated attackers, meaning attackers who do not need to log in to the website, to modify the plugin’s settings without permission. This is possible because the plugin does not have a system in place to prevent these forged requests. To protect against this type of attack, site administrators should avoid clicking on suspicious links.

Detected in:

Events Addon for Elementor open vulnerable versions: >= * <= 2.1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.