Input validation vulnerability in Ibtana – WordPress Website Builder 1.2.2

The Ibtana – WordPress Website Builder plugin for WordPress has a security vulnerability in versions up to and including 1.2.2 which can allow malicious code to be stored on webpages and executed when a user views them. This vulnerability is due to a lack of input validation and output escaping when users supply attributes such as ‘width’ and ‘height’. An attacker with contributor or higher level permissions could use this vulnerability to inject web scripts into pages which will be executed when the page is viewed.

Detected in:

Ibtana – WordPress Website Builder open vulnerable versions: >= * <= 1.2.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.