Input validation vulnerability in Xin 1.0.8.1

The Xin theme for WordPress has a security flaw that can be exploited by hackers. This can happen in versions 1.0.8.1 and below when untrusted information is used. This allows attackers to inject a PHP Object without needing to be authenticated. There is no known method for attackers to do this, but if there is another plugin or theme on the website, they could potentially delete files, get sensitive information, or run their own code.

Detected in:

Xin open vulnerable versions: >= * <= 1.0.8.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.