Input validation vulnerability in Bulk change of posts terms and post types 1.0

The Bulk change of posts terms and post types plugin for WordPress is vulnerable to a security issue called Stored Cross-Site Scripting. This security issue allows someone who is not logged in to add malicious code to a WordPress page. This code can then be run whenever someone views the page, potentially giving the attacker access to the website. The security issue affects versions 1.0 and earlier of the plugin and is caused by the plugin not properly sanitizing and escaping user input.

Detected in:

Bulk change of posts terms and post types open vulnerable versions: >= * <= 1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.