Input validation vulnerability in HelloAsso 1.1.5

The HelloAsso plugin for WordPress has a security issue called Stored Cross-Site Scripting. This problem affects all versions of the plugin, including version 1.1.5. The reason for this vulnerability is that the plugin does not properly clean and filter user input, making it possible for attackers who are logged in and have contributor-level or higher access to inject harmful code into web pages. This code will then be executed whenever a user visits the affected page.

Detected in:

HelloAsso fixed vulnerable versions: >= * <= 1.1.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.