Input validation vulnerability in Efí by Gerencianet Oficial 1.4.8

The Gerencianet plugin for WordPress can be vulnerable to Cross-Site Request Forgery if it is using an old version, up to and including 1.4.8. This is because the plugin does not have the correct security measures in place when using AJAX actions. This means that an unauthenticated attacker could potentially trick a site administrator into performing an action, such as clicking on a link, by sending a forged request.

Detected in:

Efí Bank fixed vulnerable versions:
Efí by Gerencianet Oficial fixed vulnerable versions: >= * <= 1.4.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.