Input validation vulnerability in Post to Social Media – WordPress to Hootsuite 1.4.5

The WordPress to Hootsuite plugin for WordPress is vulnerable to a type of cyber attack known as Stored Cross-Site Scripting in versions up to and including 1.4.5. This is because the plugin does not have enough security measures in place to prevent dangerous data from being put into the system. If someone with administrative level access to the system were to inject malicious code into the system, then it could be executed by any user who visits the affected page. This vulnerability only affects multi-site installations and installations where the security measure “unfiltered_html” has been disabled.

Detected in:

Post to Social Media – WordPress to Hootsuite fixed vulnerable versions: >= * <= 1.4.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.