Input validation vulnerability in WP Mailster 1.8.17.0

The WP Mailster plugin for WordPress has a security issue that makes it vulnerable to a type of attack called Stored Cross-Site Scripting. This can happen when someone uses a specific feature in the plugin called ‘mst_subscribe’. The problem is that the plugin doesn’t properly check for harmful code and doesn’t protect against it when it’s displayed to users. This means that someone with certain permissions could add harmful code to a page, and then whenever someone else views that page, the code will run.

Detected in:

WP Mailster fixed vulnerable versions: >= * <= 1.8.17.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.