Input validation vulnerability in CookieCode 2.4.4

The CookieCode plugin for WordPress has a security issue that could allow unauthorized access to websites using the plugin. This vulnerability affects versions up to and including 2.4.4, and is caused by a lack of proper protection against malicious code. This means that attackers who have administrator-level access or higher could potentially inject harmful web scripts into pages, which would then run whenever someone visits the affected page. However, this only affects websites with multiple installations and those that have disabled the “unfiltered_html” feature.

Detected in:

CookieCode open vulnerable versions: >= * <= 2.4.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.