Input validation vulnerability in All custom fields & groups 1.04

The All custom fields & groups plugin for WordPress has a security vulnerability in versions up to 1.04. If someone tricks a user into clicking on a link, they can inject malicious web scripts in the pages, which could put the user’s data at risk. This vulnerability is due to the plugin not properly filtering or protecting the information it is given, so it’s important to make sure you are using the most up-to-date version of the plugin.

Detected in:

All custom fields & groups fixed vulnerable versions: >= * <= 1.04

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.