Input validation vulnerability in Pondol Form to Mail 1.1

The Pondol Form to Mail plugin for WordPress is not secure in versions up to and including 1.1. This means that people who are not authorized to access the website can inject malicious web scripts into victims’ browsers if the victims click on a link. This is possible because the plugin does not properly escape and sanitize the user supplied value of the ‘itemid’ parameter.

Detected in:

Pondol Form to Mail open vulnerable versions: >= * <= 1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.