Input validation vulnerability in WP-dTree 4.4.5

The WP-dTree plugin for WordPress has a security issue in some versions that can allow unauthenticated attackers to inject malicious web scripts into pages. This security issue exists in versions up to and including 4.4.5 and is caused by the plugin not properly sanitizing user input or escaping output. If an attacker is able to inject malicious web scripts into a page, those web scripts will execute every time someone accesses the page.

Detected in:

WP-dTree open vulnerable versions: >= * <= 4.4.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.