Input validation vulnerability in Sitekit 1.4

The Sitekit plugin for WordPress is vulnerable to a type of security problem called Stored Cross-Site Scripting. This is a type of attack that can occur when an attacker with a certain level of access, called Contributor-level access or higher, is able to inject malicious code into the plugin. This malicious code can then be used to execute unwanted activity on the pages that contain the code when a user visits them. Versions of the Sitekit plugin up to and including 1.4 are affected by this vulnerability. To protect against this vulnerability, the plugin should be updated to a version with improved input sanitization and output escaping.

Detected in:

Sitekit open vulnerable versions: >= * <= 1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.