Input validation vulnerability in Userback 1.0.13

The Userback plugin for WordPress is vulnerable to a type of cyber attack called Cross-Site Request Forgery. This attack can be used in versions of the plugin up to version 1.0.13. This is because the plugin does not check to see if requests are genuine before carrying them out. This means that if an attacker can make a site administrator click on a link, they can use the attack to change the Userback user settings without needing to be authenticated.

Detected in:

Userback fixed vulnerable versions: >= * <= 1.0.13

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.