Input validation vulnerability in Free WordPress Lead Generation Opt in, Free Popups, Generated Lead Email Popup, Exit-Intent Popup – NotifyVisitors 1.0

The NotifyVisitors plugin for WordPress is not secure in versions up to 1.0. This plugin is used in multi-site installations and installations where unfiltered_html has been disabled. An attacker with administrator-level access can inject web scripts into pages that will execute whenever a user visits the injected page. This could allow the attacker to access private information and take control of the website. To stay safe, make sure you are using the latest version of the NotifyVisitors plugin.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.