Input validation vulnerability in My Link Order 4.3

The My Link Order plugin for WordPress has a vulnerability that could allow an attacker to inject malicious code into website pages. This vulnerability exists in versions up to and including 4.3. It is triggered when the ‘cats’ and ‘hdnCatID’ parameters lack input sanitization and output escaping. When a user visits an affected page, any malicious code injected into it will execute. The vulnerability can also be exploited using Cross-Site Request Forgery.

Detected in:

My Link Order fixed vulnerable versions: >= * <= 4.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.