Input validation vulnerability in CRM and Lead Management by vcita 2.6.2

The CRM and Lead Management by vcita plugin for WordPress has a security flaw that could cause harm to users. If someone with the “edit_posts” permission, such as a contributor or higher, uses the “email” parameter in versions up to and including 2.6.2, they could inject web scripts into pages. These web scripts would then run as soon as someone visits the injected page, which could cause harm to the user. To protect against this, users should upgrade to the latest version of the plugin.

Detected in:

CRM and Lead Management by vcita fixed vulnerable versions: >= * <= 2.6.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.