Input validation vulnerability in Connect Matomo (WP-Matomo, WP-Piwik) 1.0.28

The WP-Matomo Integration (WP-Piwik) plugin for WordPress is vulnerable to malicious code being injected into webpages viewed by users. This vulnerability exists in versions up to and including 1.0.28 and is caused by the plugin not properly checking and preventing malicious code from being inputted into the website. Attackers with contributor-level and above permissions can inject arbitrary web scripts in pages that will be executed whenever a user accesses an injected page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.