Input validation vulnerability in Simple Sticky Footer 1.3.2

The Simple Sticky Footer plugin for WordPress (version 1.3.3 or earlier) had several security problems that allowed attackers to take control of an administrator’s account. This could be used to change the plugin settings or conduct an attack called Cross-Site Scripting (XSS). The XSS attack could be done using the simple_sf_width or simple_sf_style parameter on the simple-simple-sticky-footer page in wp-admin/themes.php.

Detected in:

Simple Sticky Footer open vulnerable versions: >= * <= 1.3.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.