Input validation vulnerability in Autocomplete Location field Contact Form 7 2.0

The WordPress plugin Autocomplete Location field Contact Form 7 is vulnerable to a security issue in all versions up to and including 2.0. This security issue is called Stored Cross-Site Scripting and it happens when an attacker with administrator-level permissions or higher injects web scripts into pages. If a user accesses the page with the injected script, it will execute. This security issue only affects WordPress installations with multiple sites and installations where unfiltered HTML has been disabled.

Detected in:

Autocomplete Location field Contact Form 7 fixed vulnerable versions: >= * <= 2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.