Input validation vulnerability in yurl-retwitt 1.4

There are security weaknesses in the yURL ReTwitt plugin version 1.4 and earlier for WordPress that allow people from outside the website to gain control of an administrator’s account. This allows them to make requests that can cause a Cross-Site Scripting (XSS) attack on the website. The attackers can do this by using the yurl_login or yurl_anchor parameter found on the yurl page of the wp-admin/options-general.php file.

Detected in:

yurl-retwitt open vulnerable versions: >= * <= 1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.