Input validation vulnerability in WP-FormAssembly 2.0.7

The WP-FormAssembly plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting. In versions up to and including 2.0.7, the plugin does not properly check user supplied information or protect against malicious scripts. This leaves the door open for attackers with contributor-level or higher permissions to inject malicious scripts into pages that will execute when any user visits that page.

Detected in:

WP-FormAssembly open vulnerable versions: >= * <= 2.0.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.