Input validation vulnerability in GamiPress – Button 1.0.4

. The GamiPress – Button plugin for WordPress has a security vulnerability that could allow an attacker with contributor level permissions or higher to inject malicious web scripts into pages. If someone visits an affected page, the script could be executed. This vulnerability affects versions of the plugin up to and including version 1.0.4 because the plugin does not properly sanitize user supplied attributes and does not escape output.

Detected in:

GamiPress – Button fixed vulnerable versions: >= * <= 1.0.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.