Input validation vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 3.8.1

The Wordfence Security plugin for WordPress is vulnerable to a type of security attack called Stored Cross-Site Scripting. This vulnerability exists in versions of the plugin up to and including 3.8.1. It happens when the plugin does not filter or sanitize the data it receives and does not properly escape it before displaying it to the user. This makes it possible for attackers to inject malicious web scripts into pages that will run whenever a user views that page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.