Input validation vulnerability in Auto Excerpt everywhere 1.5

The Auto Excerpt everywhere plugin for WordPress is vulnerable to a type of attack called a Cross-Site Request Forgery. It affects all versions up to and including version 1.5. This is because the plugin’s security measures, called nonce validation, are either missing or incorrect. This allows unauthenticated attackers to modify the plugin’s settings by tricking a site administrator into clicking on a link or performing another action.

Detected in:

Auto Excerpt everywhere open vulnerable versions: >= * <= 1.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.