Input validation vulnerability in teachPress 9.0.3

The teachPress plugin for WordPress is vulnerable to a security issue known as Reflected Cross-Site Scripting. This means that if someone can trick a user into clicking a link, then they can inject web scripts that will execute on the user’s web page. This is possible because the teachPress plugin does not properly check the inputs of certain parameters (such as meta_field_id and cite_id) and fails to escape output in versions 9.0.2 and earlier.

Detected in:

teachPress open vulnerable versions: >= * < 9.0.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.