Input validation vulnerability in My WP Customize Admin/Frontend 1.21.1

The My WP Customize Admin/Frontend plugin for WordPress is vulnerable to a security issue called Stored Cross-Site Scripting. This issue can be found in versions of the plugin up to and including version 1.21.0. This vulnerability can be exploited by an attacker with administrator-level permissions or higher. It allows them to add malicious web scripts to pages, which will be executed whenever someone visits the page. This type of attack is only possible on multi-site installations and installations where the unfiltered_html setting has been disabled.

Detected in:

My WP Customize Admin/Frontend fixed vulnerable versions: >= * < 1.21.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.