Input validation vulnerability in Calculated Fields Form 1.2.28

The Calculated Fields Form plugin for WordPress is vulnerable to a type of attack known as an Open Redirect. This is because the plugin’s shortcodes do not properly sanitize or escape user input and output. This means that attackers with at least contributor-level permissions can redirect users when they visit a page that has been injected with malicious code. This vulnerability affects all versions of the plugin up to version 1.2.29.

Detected in:

Calculated Fields Form fixed vulnerable versions: >= * <= 1.2.28

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.