Input validation vulnerability in Profile Extra Fields by BestWebSoft 1.0.6

The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to Reflected Cross-Site Scripting, a type of security vulnerability. This means that attackers can inject malicious code into web pages that users can see. In versions of the plugin before 1.0.6, there wasn’t enough input sanitization and output escaping which made it possible for unauthenticated attackers to do this. To protect against this, users should make sure they are using the most up-to-date version of the plugin.

Detected in:

Profile Extra Fields by BestWebSoft open vulnerable versions: >= * < 1.0.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.