Input validation vulnerability in WP-FormAssembly 2.0.11

The WP-FormAssembly plugin for WordPress has a security issue called Stored Cross-Site Scripting. This happens when the plugin’s ‘formassembly’ shortcode is used, and can affect all versions up to 2.0.11. The problem is caused by not properly checking and protecting user-provided information. This can allow attackers who are logged in as contributors or higher to insert harmful web scripts into pages that will run when someone views the page.

Detected in:

WP-FormAssembly open vulnerable versions: >= * <= 2.0.11

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.