Input validation vulnerability in GB Team Stats 1.5.1

The GB Team Stats WordPress plugin, up to version 1.5.1, is vulnerable to unauthenticated attackers injecting malicious web scripts into pages. An attacker can exploit this vulnerability if they can convince a user to perform an action, such as clicking on a link. The vulnerability is caused by insufficient input sanitization and output escaping of the ‘data’ parameter.

Detected in:

GB Team Stats open vulnerable versions: >= * <= 1.5.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.