Input validation vulnerability in News Flash 1.1.0

The News Flash theme for WordPress has a security vulnerability that allows attackers to inject a harmful PHP Object. This can only be done by someone with Editor-level access or higher, and only if they have untrusted input from the “newsflash_post_meta” value. There is no known way for attackers to exploit this vulnerability, but if the target system has other plugins or themes installed, it could potentially allow them to do things like delete files, access sensitive information, or run code.

Detected in:

News Flash open vulnerable versions: >= * <= 1.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.