Input validation vulnerability in Contact List – Easy Contact Manager, Address Book and Business Directory Plugin 2.9.41

The Contact List plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting. This means that a malicious user could inject code into the plugin that could be used to take control of a website or access confidential information. This vulnerability existed in versions of the plugin up to 2.9.41 and was caused by the plugin not properly validating and escaping user input. This allowed attackers to trick a user into clicking a link or performing an action that would execute the injected code.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.