Input validation vulnerability in Parsi Date 5.1.1

The Parsi Date plugin for WordPress has a security issue called Reflected Cross-Site Scripting. This happens because of a function called add_query_arg that is used without proper protection in all versions up to 5.1.1. This allows attackers who are not logged in to insert harmful web scripts on pages, as long as they can trick a user into clicking on a link.

Detected in:

Parsi Date fixed vulnerable versions: >= * <= 5.1.1
پارسی دیت – Parsi Date fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.