Input validation vulnerability in Advanced Control Manager for WordPress by ItalyStrap 2.16.0

The tool called “Advanced Control Manager for WordPress” by ItalyStrap, which can be added to WordPress, has a security issue. This issue, known as Stored Cross-Site Scripting, affects all versions up to 2.16.0. This means that the tool does not properly clean up or escape certain inputs and outputs, making it possible for someone with contributor-level access or higher to add harmful web scripts to pages. These scripts can then run whenever someone visits the affected page.

Detected in:

Advanced Control Manager for WordPress by ItalyStrap open vulnerable versions: >= * <= 2.16.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.