Input validation vulnerability in Saan World Clock 1.8

The Saan World Clock plugin for WordPress is not secure in versions up to and including 1.8. People with contributor-level permissions or higher can inject malicious web scripts into pages which can be executed when someone visits the page. This is possible because the plugin does not properly check and secure user inputs before displaying them.

Detected in:

Saan World Clock fixed vulnerable versions: >= * <= 1.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.