Input validation vulnerability in VK All in One Expansion Unit 9.88.1.0

The VK All in One Expansion Unit plugin for WordPress contains a security vulnerability which affects versions up to and including 9.88.1.0. This vulnerability could allow an attacker with contributor-level permissions or higher to inject malicious web scripts into pages on the website. When a user visits one of these pages, the malicious web scripts will be executed. This vulnerability is due to the plugin not properly sanitizing user input, and not properly escaping output.

Detected in:

VK All in One Expansion Unit fixed vulnerable versions: >= * <= 9.88.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.