Input validation vulnerability in Easy Social Icons 3.2.4

The Easy Social Icons plugin for WordPress has a security issue that allows attackers with a contributor-level or higher permission to inject malicious web scripts into pages. This issue is present in all versions up to 3.2.4, as the plugin does not properly sanitize user input or escape output. When a user visits an injected page, the malicious web scripts will be executed.

Detected in:

Easy Social Icons fixed vulnerable versions: >= * <= 3.2.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.