Input validation vulnerability in YML for Yandex Market 4.7.2

The Yandex Market plugin for WordPress, specifically the YML feature, has a security issue that could allow malicious hackers to inject harmful scripts onto web pages. This vulnerability is present in all versions up to 4.7.2 and is caused by not properly filtering and protecting input and output. This means that if a user is tricked into clicking on a link, the attacker could run their own code on the page.

Detected in:

YML for Yandex Market fixed vulnerable versions: >= * <= 4.7.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.