Input validation vulnerability in Login rebuilder 1.2.0

The Login rebuilder plugin for WordPress is not secure in versions up to 1.2.0. This means that someone who is not authorized to make changes can possibly change the plugin’s settings just by getting a website administrator to do something like clicking on a link. This is possible because the plugin does not have something called nonce validation on the properties() function.

Detected in:

Login rebuilder fixed vulnerable versions: >= * < 1.2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.