Input validation vulnerability in HostFact bestelformulier integratie 1.1

The HostFact ordering form integration plugin for WordPress is at risk for a type of hack called Stored Cross-Site Scripting. This can happen through the plugin’s ‘ordering form’ shortcut in versions 1.1 and below. The plugin does not properly clean up or protect against potentially harmful information that users input. This means that someone who has contributor-level access or higher can add harmful code to a page, and it will run whenever someone visits that page.

Detected in:

HostFact bestelformulier integratie fixed vulnerable versions: >= * <= 1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.