Input validation vulnerability in WangGuard 1.7.2

The WangGuard plugin for WordPress is vulnerable to a type of attack known as Reflected Cross-Site Scripting in versions before 1.7.2. This means if an unauthenticated attacker can successfully trick a user into clicking on a link, they can inject malicious web scripts into the page that will execute. This is because of an issue with insufficient input sanitization and output escaping on the ‘a’ parameter.

Detected in:

WangGuard open vulnerable versions: >= * < 1.7.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.