Input validation vulnerability in Editorial Calendar 3.7.12

The Editorial Calendar plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting. This means that attackers with contributor-level permissions or higher can inject malicious web scripts into WordPress pages. Once injected, these malicious scripts will then be executed whenever someone visits an affected page. This vulnerability affects versions of the plugin up to and including 3.7.12 because they did not properly secure their inputs and outputs.

Detected in:

Editorial Calendar open vulnerable versions: >= * <= 3.8.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.