Input validation vulnerability in Memberlite Shortcodes 1.3.9

The Memberlite Shortcodes plugin for WordPress is vulnerable to an attack which allows malicious code to be stored and then executed when someone views a page created with the plugin. This attack affects version 1.3.8 and earlier and is due to the plugin not properly checking the input and preventing the malicious code from being inserted. This means that users with contributor level access and above can inject malicious web scripts into pages which will execute when any user views the page.

Detected in:

Memberlite Shortcodes open vulnerable versions: >= * < 1.3.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.