Input validation vulnerability in WooFramework Tweaks 1.0.1

The WooFramework Tweaks plugin for WordPress is vulnerable to a type of cyber attack called Reflected Cross-Site Scripting in versions up to, and including, 1.0.1. This type of attack happens when someone tricks a user into clicking on a link to a malicious website, and that website is then able to inject malicious scripts into pages that the user visits. The vulnerability has to do with the plugin not adequately protecting against this type of attack, by not properly checking the input to the link and not properly escaping the output.

Detected in:

WooFramework Tweaks open vulnerable versions: >= * <= 1.0.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.