Input validation vulnerability in Custom Post Carousels with Owl 1.4.6

This plugin for WordPress, called ‘Custom Post Carousels with Owl’, is vulnerable to a type of attack called ‘Stored Cross-Site Scripting’. This type of attack affects versions up to and including 1.4.6. It means that users with access to edit pages (such as editors) can inject malicious code into pages, which will then run when other users view the page. This makes it dangerous for anyone who views the page.

Detected in:

Custom Post Carousels with Owl fixed vulnerable versions: >= * <= 1.4.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.