Input validation vulnerability in Shariff Wrapper 4.6.9

The Shariff Wrapper plugin for WordPress has a security vulnerability that allows attackers to insert malicious scripts through the ‘shariff’ shortcode. This can happen if the attacker has contributor or higher level permissions. It is caused by not properly sanitizing and escaping user input attributes such as ‘info_text’. This means that when a user clicks on the information icon on a page, the malicious script will be executed.

Detected in:

Shariff Wrapper fixed vulnerable versions: >= * <= 4.6.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.