Input validation vulnerability in ShiftController Employee Shift Scheduling 4.9.57

A plugin called ShiftController Employee Shift Scheduling has a security flaw that allows someone to inject harmful code through a specific cookie. This is possible in versions 4.9.57 and below. If the attacker has certain access levels, they can cause damage by injecting a certain type of code. If there is another plugin or theme installed on the affected system, the attacker could have even more capabilities, such as deleting files, accessing sensitive information, or running their own code.

Detected in:

ShiftController Employee Shift Scheduling fixed vulnerable versions: >= * <= 4.9.57

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.