Input validation vulnerability in Terms descriptions 3.4.4

The Terms Descriptions plugin for WordPress is vulnerable to an attack called Reflected Cross-Site Scripting. This attack can be done by an unauthenticated attacker to inject malicious web scripts into pages on the website. If a user clicks on a link that the attacker has created, these web scripts can be executed. This vulnerability exists in all versions of the Terms Descriptions plugin up to 3.4.4 due to lack of input sanitization and output escaping.

Detected in:

Terms descriptions open vulnerable versions: >= * <= 3.4.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.