Input validation vulnerability in Easy SVG Allow 1.0

The Easy SVG Allow plugin for WordPress is vulnerable to a security issue called Stored Cross-Site Scripting. This security issue could allow someone with author-level access and above to inject malicious code into pages on a WordPress website. This malicious code would execute every time someone views the page. All versions of Easy SVG Allow, up to and including 1.0, have this security flaw due to the plugin not properly sanitizing and escaping input.

Detected in:

Easy SVG Allow open vulnerable versions: >= * <= 1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.