Input validation vulnerability in Premium Addons Pro for Elementor 2.9.12

The Premium Addons PRO plugin for WordPress has a security issue called Stored Cross-Site Scripting. This can happen through the Global Badge module in all versions up to 2.9.12. This is because the plugin does not properly clean or protect the information that is entered and displayed. This allows attackers with contributor-level access or higher to add harmful web scripts to pages. Whenever a user visits one of these pages, the script will run.

Detected in:

Premium Addons Pro for Elementor fixed vulnerable versions: >= * <= 2.9.12

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.