Input validation vulnerability in GF Windcave Free 1.4.2

The GF Windcave Free plugin for WordPress has a security vulnerability which can be exploited by an unauthenticated attacker. They can inject malicious web scripts into pages by using malicious URLs, and if a user clicks on the link, the web scripts will be executed. This issue affects versions of the plugin up to and including 1.4.3 due to insufficient sanitization and escaping of input.

Detected in:

GF Windcave Free fixed vulnerable versions: >= * <= 1.4.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.