Input validation vulnerability in WP Smart Import : Import any XML File to WordPress 1.0.7

The plugin WP Smart Import for WordPress is at risk of a security issue known as Stored Cross-Site Scripting. This can happen in any version of the plugin up to 1.0.7 because it does not properly clean up and protect the input and output. This means that someone who has access to the site as an author or higher could potentially insert their own code into a page that will run whenever someone visits that page.

Detected in:

WP Smart Import : Import any XML File to WordPress open vulnerable versions: >= * <= 1.0.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.