Input validation vulnerability in Calculated Fields Form 5.2.61

The Calculated Fields Form plugin for WordPress has a security issue that allows hackers to inject harmful code through the admin settings. This can happen on versions up to 5.2.61 and is caused by not properly checking and filtering the input and output. This means that attackers who have administrator-level access can add their own code to pages, which will run whenever someone visits those pages. This only affects websites with multiple sites or where the option to filter HTML has been turned off.

Detected in:

Calculated Fields Form fixed vulnerable versions: >= * <= 5.2.61

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.