Input validation vulnerability in Count per Day 3.2.6

The Count per Day plugin for WordPress has an issue that can allow unauthenticated attackers to inject arbitrary web scripts into pages. This issue is present in versions before 3.2.6, and is caused by an inadequate handling of input data and output coding. If a user clicks on a link that the attacker has tricked them into clicking, the injected scripts can execute. To protect your WordPress website, make sure you are using the latest version (3.2.6) of Count per Day.

Detected in:

Count per Day open vulnerable versions: >= * < 3.2.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.