Input validation vulnerability in Same Category Posts 1.1.19

The Same Category Posts plugin for WordPress has a security issue that allows attackers to insert harmful code into pages. This can be done through the widget title placeholder feature in versions 1.1.19 and below. The problem is caused by a function that decodes special characters, making it possible for attackers with Author-level access or higher to inject their own code into pages. This can be dangerous for users who visit the affected pages.

Detected in:

Same Category Posts fixed vulnerable versions: >= * <= 1.1.19

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.