Input validation vulnerability in ImageMapper 1.2.6

The ImageMapper plugin for WordPress is not secure in versions up to 1.2.6. Attackers who are not authenticated, meaning they don’t have permission to access the website, can still update the plugin settings. This could be done by tricking a site administrator into clicking a link. Nonce validation, which is a security measure, is missing or incorrect in the plugin, making this possible.

Detected in:

ImageMapper open vulnerable versions: >= * <= 1.2.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.