Input validation vulnerability in WP Category Post List Widget 2.0.3

The WP Category Post List Widget plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting. This type of attack happens when malicious code is stored in a website and is executed every time a user visits the website. In this case, the plugin is vulnerable to this type of attack because it does not properly clean or protect the data that is being stored. This vulnerability affects versions 2.0.3 and below, and can be exploited by attackers who have contributor-level access or higher.

Detected in:

WP Category Post List Widget open vulnerable versions: >= * <= 2.0.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.