Input validation vulnerability in WeSecur Security – Antivirus, Malware Scanner and Protection for your WordPress 1.2.1

The WeSecur Security plugin for WordPress has a security issue that makes it vulnerable to a type of attack called Stored Cross-Site Scripting. This attack can be carried out by someone with administrator-level access or above and it affects versions of the plugin up to and including 1.2.1. It works by allowing the attacker to inject web scripts into pages that will be executed each time someone visits them. This issue only affects WordPress installations with multiple sites and those where the unfiltered_html feature has been disabled.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.