Input validation vulnerability in Widget Settings Importer/Exporter 1.5.3

The Widget Settings Importer/Exporter Plugin for WordPress is vulnerable to a form of malicious attack called Stored Cross-Site Scripting. This type of attack happens when a hacker is able to inject malicious code into a website that will then run whenever someone visits the website. The vulnerability affects versions of the plugin up to 1.5.3 and occurs because the plugin does not properly sanitize and escape user input, allowing hackers with subscriber-level permissions and above to inject malicious code into pages.

Detected in:

Widget Settings Importer/Exporter open vulnerable versions: >= * <= 1.5.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.