Input validation vulnerability in Simple Image Popup 1.3.6

The Simple Image Popup plugin for WordPress is not secure in versions up to and including 1.3.6. Attackers with administrator permissions or higher can inject dangerous web scripts into pages. This can cause the scripts to run whenever a user visits an infected page. This only affects multi-site installations and installations where extra security has been disabled.

Detected in:

Simple Image Popup open vulnerable versions: >= * <= 1.3.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.