Input validation vulnerability in CallRail Phone Call Tracking 0.4.9

The CallRail Phone Call Tracking plugin for WordPress is not secure in versions 0.4.9 and older. It is possible for someone who is not authorized to do something (like click a link) to inject malicious JavaScript into posts and pages. This malicious code will then run each time someone visits the post or page.

Detected in:

CallRail Phone Call Tracking fixed vulnerable versions: >= * <= 0.4.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.