Input validation vulnerability in Theater for WordPress 0.18.3

The Theater plugin for WordPress is vulnerable to a kind of security attack called Stored Cross-Site Scripting, which can affect all versions of the plugin up to and including 0.18.3. This attack can be used by anyone with administrator-level access to the site to inject malicious web scripts into certain pages. These scripts will then run whenever someone visits the page they were injected into. This vulnerability only affects multi-site installations and installations where unfiltered_html has been disabled.

Detected in:

Theater for WordPress open vulnerable versions: >= * <= 0.18.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.