Input validation vulnerability in WordPress Calls to Action 2.2.8

The WordPress Calls to Action plugin is vulnerable to an attack called Stored Cross-Site Scripting in older versions (before 2.2.8) because it does not properly filter or secure the data within. This means that an unauthenticated attacker can add code to webpages which will run automatically when someone visits the page.

Detected in:

WordPress Calls to Action open vulnerable versions: >= * < 2.2.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.