Input validation vulnerability in User Access Manager 1.2.14

The User Access Manager plugin for WordPress is not secure in versions up to, and including, 1.2.14. An unauthenticated attacker can inject malicious web scripts into pages, and if a user clicks on a link, the scripts will execute. This is possible because the plugin does not properly check user input or correctly escape output.

Detected in:

User Access Manager fixed vulnerable versions: >= * <= 1.2.14

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.