Input validation vulnerability in Livefyre Comments 3 4.1.4

The Livefyre Comments 3 plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting. This type of attack can be used by authenticated attackers, who have at least subscriber-level permissions, to inject malicious web scripts into pages. These malicious scripts will then be executed every time a user visits the affected page. This vulnerability affects any version of the plugin up to and including version 4.1.4 as it does not have the necessary security measures in place to prevent the attack.

Detected in:

Livefyre Comments 3 open vulnerable versions: >= * <= 4.1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.