Input validation vulnerability in WxSync-标准云微信公众号文章免费采集-任意公众号自动采集付费购买 2.7.23

The WxSync plugin for WordPress is a tool that can be vulnerable to a type of attack called Stored Cross-Site Scripting. This type of attack exists in versions up to and including 2.7.23 of the plugin, because there are not enough safeguards in place to protect it. If an attacker has access with a level of permission like “contributor” or higher, they can inject web scripts into pages that will run automatically when a user goes to the page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.