Input validation vulnerability in alfred24 Click & Collect 1.1.7

The Alfred24 Click & Collect plugin for WordPress is not secure in versions up to and including 1.1.7. This is because it does not properly check and filter the information that is input into the system. This makes it possible for people with administrator access to insert malicious web scripts into pages that will run when a user views them. This problem only affects multi-site installations and those where the “”unfiltered_html”” setting is disabled.

Detected in:

alfred24 Click & Collect open vulnerable versions: >= * <= 1.1.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.