Input validation vulnerability in Smart Post Show – Post Grid, Post Carousel, Post Slider, Post Timeline, Post Table, and List Category Posts, Latest Posts, Recent Posts, Popular Posts and More 3.0.0

The Smart Post Show feature for WordPress is at risk for an attack called Stored Cross-Site Scripting. This can happen when a user chooses the Pagination Color option in versions up to 3.0.0. The problem is caused by not properly filtering and escaping the input. This means that someone with editor-level access can inject dangerous scripts into pages that will run when a user visits the affected page. This only affects installations with multiple sites or those that have disabled the unfiltered_html option.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.