Input validation vulnerability in Custom 404 Pro 3.10.0

The Custom 404 Pro plugin for WordPress has a security flaw that can be exploited by unauthenticated attackers. This flaw allows them to inject arbitrary web scripts into pages, which will be executed every time a user visits the injected page. This flaw exists in all versions of the plugin up to and including 3.10.0, and is caused by the lack of proper input sanitization and output escaping.

Detected in:

Custom 404 Pro open vulnerable versions: >= * <= 3.10.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.