Input validation vulnerability in Instagram for WordPress 2.1.6

The Instagram for WordPress plugin for WordPress is vulnerable to a security issue called Stored Cross-Site Scripting. Versions of the plugin up to and including 2.1.6 have a flaw in the way it handles user input and output. This means that if an attacker with the correct permissions (contributor level or higher) is able to access the plugin, they can inject malicious web scripts into pages. These scripts will be executed every time a user visits the page.

Detected in:

Instagram for WordPress open vulnerable versions: >= * <= 2.1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.