Input validation vulnerability in Category Order and Taxonomy Terms Order 1.4.6.0

The Category Order and Taxonomy Terms Order plugin for WordPress is vulnerable to a type of malicious attack known as Cross-Site Scripting. This plugin is used to order categories and taxonomy terms within a WordPress site. In versions up to and including 1.4.6.0 of the plugin, there is not enough protection from this kind of attack. This means that attackers can use the plugin to insert harmful web scripts into a victim’s browser.

Detected in:

Category Order and Taxonomy Terms Order fixed vulnerable versions: >= * < 1.4.6.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.