Input validation vulnerability in Category Post List Widget 2.0

The Category Post List Widget plugin for WordPress is vulnerable to malicious code being inserted into its pages. This malicious code can be inserted by unauthenticated attackers and will execute whenever a user visits a page with the malicious code. This vulnerability exists in versions up to and including version 2.0 of the plugin and is caused by the lack of input sanitization, output escaping and a nonce check on the ‘get_cplw_settings’ function.

Detected in:

Category Post List Widget open vulnerable versions: >= * <= 2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.