Input validation vulnerability in User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin 3.1.4

A popular WordPress plugin called “User Registration – Custom Registration Form, Login Form, and User Profile” has a security issue that could allow attackers to inject harmful code into web pages. This could happen because the plugin does not properly clean and protect user input. However, this vulnerability can only be exploited if the attacker tricks a user into logging in and accessing a page with the injected code. This is a small risk, but the plugin’s developers have released an update to fix the issue.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.