Also, in Jetpack Protect:
The Quantity Plus Minus Button for WooCommerce by CodeAstrology plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.9. This is due to missing or incorrect nonce validation on the wqpmb_form_submit function. This makes it possible for unauthenticated attackers to update the plugin’s options via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Any clue?
Thanks for informing us. We will check and fix it in next update.
Thanks
Is the next update planned urgently. I’m considering my options to remove and replace the plugin in several sites as I can’t have them running with known vulnerabilities, but that is a time-consuming process, so I’m hoping the ‘Update Available’ notice appears in my sites admin very soon?
Cheers
Today I will check out it.
Hello @cesarmarti and @c4concepts
I have added Nonce verification for form.
Please update your plugin.