Input validation vulnerability in IndieWeb 4.0.5

The plugin called IndieWeb for WordPress has a security issue where someone can insert malicious code through the ‘Telephone’ section. This affects all versions up to 4.0.5 and can be done by someone with author level access or higher. This means that when a user visits a page with the malicious code, it will run without their knowledge.

Detected in:

IndieWeb fixed vulnerable versions: >= * <= 4.0.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.