Input validation vulnerability in WP Matterport Shortcode 2.1.4

The WP Matterport Shortcode plugin for WordPress is vulnerable to a security risk called Stored Cross-Site Scripting. This security risk could be exploited by an attacker who has access to a WordPress account with Contributor-level permissions and above. If exploited, this security risk would allow the attacker to inject code into pages that execute when someone visits the page. Versions of the WP Matterport Shortcode plugin up to and including 2.1.4 are vulnerable to this security risk due to a lack of safeguards preventing malicious user input and output.

Detected in:

Matterport Shortcode fixed vulnerable versions:
WP Matterport Shortcode open vulnerable versions: >= * <= 2.1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.