Input validation vulnerability in Bukza 2.0.0

The Bukza plugin for WordPress has a security issue called Stored Cross-Site Scripting. This happens when the plugin’s ‘bukza’ shortcode is used, which can be found in all versions up to 2.0.0. The problem is caused by not properly cleaning up information provided by users and not properly securing the output. This allows people who are logged in as contributors or higher to add harmful code to pages that will run whenever someone views the infected page.

Detected in:

Bukza fixed vulnerable versions: >= * <= 2.0.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.