Input validation vulnerability in Ultimate Push Notifications ( Mobile / Desktop ), Receive Notification From WooCommerce, BuddyPress, WordPress Default Events & Many More 1.1.8

The plugin called “Ultimate Push Notifications” for the website platform WordPress has a security issue in versions 1.1.8 and below. This issue, known as Reflected Cross-Site Scripting, occurs because the plugin does not properly clean up user input and output. This means that someone who is not logged into the website can add harmful code to a page by tricking a user into clicking on a link.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.