Input validation vulnerability in SiteOrigin Widgets Bundle 1.60.0

The SiteOrigin Widgets Bundle plugin for WordPress has a security issue that could allow someone to insert harmful code into a webpage. This can be done by using the ‘siteorigin_widget’ shortcode in versions 1.60.0 and below. This vulnerability is due to not properly checking and filtering the information that users input, and not properly securing the output information. This means that someone with contributor-level access or higher can add code to a webpage that will run when someone visits that page.

Detected in:

SiteOrigin Widgets Bundle fixed vulnerable versions: >= * <= 1.60.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.