Input validation vulnerability in WPDBSpringClean 1.6

The WPDBSpringClean plugin for WordPress has a security vulnerability that allows attackers to inject malicious code into pages on a WordPress website. All versions of this plugin up to and including version 1.6 are affected. This vulnerability is caused by the plugin not properly sanitizing and escaping the ‘tab’ parameter. If an attacker can get a user to click on a link, they can use this vulnerability to inject malicious code that will execute on the user’s computer.

Detected in:

WPDBSpringClean open vulnerable versions: >= * <= 1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.