Input validation vulnerability in Structured Content (JSON-LD) #wpsc 1.6.1

The plugin used for organizing content on WordPress is at risk for a type of hacking called Stored Cross-Site Scripting. This can happen through the Classic Editor shortcodes in versions 1.6.1 and below because the plugin does not properly clean up the input or output of information. This means that people who have at least contributor-level permissions can insert harmful code into pages that will run when someone views that page.

Detected in:

Structured Content (JSON-LD) #wpsc open vulnerable versions: >= * <= 1.6.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.