Input validation vulnerability in Simple Counter 1.0.2

The Simple Counter plugin for WordPress is vulnerable to a type of cyberattack known as Stored Cross-Site Scripting in all versions up to and including 1.0.2. This type of attack can occur when an attacker, who has been given administrator-level permissions or higher, is able to inject malicious code into a page. This malicious code will be executed whenever somebody visits the page, and could be used to do things like steal information or take control of the user’s computer. This vulnerability only affects multi-site installations and installations where unfiltered_html has been disabled.

Detected in:

Simple Counter open vulnerable versions: >= * <= 1.0.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.