Input validation vulnerability in Add Custom Post Type into Post Query 1.03

The Add Custom Post Type into Post Query plugin for WordPress is vulnerable to a security issue which could allow unauthenticated attackers to inject malicious code into pages. This issue exists in versions up to, and including, version 1.03. Attackers could exploit this vulnerability by tricking a user into clicking on a malicious link. This is possible because the plugin does not properly sanitize or escape user input.

Detected in:

Add Custom Post Type into Post Query fixed vulnerable versions: >= * <= 1.03

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.