Input validation vulnerability in Flash News *

The Flash News Theme for WordPress is vulnerable to a few different security issues. Cross-Site Scripting (XSS) is one of them, which means attackers can inject their own code into the website. This code can then be executed in the browser of any user who visits the website. The plugin is also vulnerable to Arbitrary File Upload, Denial of Service Attacks, and Full Path Disclosure. This makes it possible for malicious users to upload malicious files to the website server, deny access to legitimate users, and view sensitive information like the full path of the WordPress installation.

Detected in:

Flash News fixed vulnerable versions: >= * <= *

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.