Input validation vulnerability in Custom Field For WP Job Manager 1.1

The Custom Field For WP Job Manager plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting in versions up to 1.1. This attack can happen when the plugin does not properly sanitize input and escape output, making it possible for attackers with administrator access to inject malicious web scripts into pages. This type of attack only affects multi-site installations and installations with unfiltered_html disabled.

Detected in:

Custom Field For WP Job Manager fixed vulnerable versions: >= * <= 1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.