Input validation vulnerability in WP Proposals 2.3

The plugin called WP Proposals, which is used for WordPress websites, has a security issue known as Stored Cross-Site Scripting. This means that in versions 2.3 and below, the plugin does not properly clean up the input and output of certain code, making it possible for attackers with contributor-level access or higher to insert harmful web scripts into pages. This can cause these scripts to run whenever a user opens the affected page.

Detected in:

WP Proposals open vulnerable versions: >= * <= 2.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.