Input validation vulnerability in Glossary by WPPedia – Best Glossary plugin for WordPress 1.3.0

The Glossary plugin for WordPress, called WPPedia, has a security vulnerability that allows attackers with Administrator-level access or higher to inject a PHP Object. This can potentially lead to malicious actions such as deleting files, accessing sensitive information, or executing code. This vulnerability affects all versions of the plugin up to 1.3.0 and is caused by untrusted input from the ‘posttypes’ parameter. It is important to note that this vulnerability only has an impact if the website has another plugin or theme with a known vulnerability installed.

Detected in:

Glossary by WPPedia – Best Glossary plugin for WordPress open vulnerable versions: >= * <= 1.3.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.