Input validation vulnerability in Web Instant Messenger 1.1.2

The Web Instant Messenger and LocalWeb In One plugins for WordPress are both vulnerable to a form of attack called Stored Cross-Site Scripting. This attack can happen in versions of these plugins up to and including 1.6.4. Unfortunately, the latest version of Web Instant Messenger, 1.1.2, is still vulnerable and has not been fixed. This attack involves an attacker injecting malicious code into a webpage which will execute when a user visits the page.

Detected in:

LocalWeb All In One fixed vulnerable versions: >= * <= 1.6.4
Web Instant Messenger open vulnerable versions: >= * <= 1.1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.