Input validation vulnerability in Login Screen Manager 3.5.2

The Login Screen Manager plugin for WordPress is a tool that is used to manage the way users login to WordPress. A vulnerability has been discovered in versions of this tool up to and including 3.5.2 that makes it possible for an attacker with administrator level permissions to inject arbitrary web scripts into pages on the website. This can cause the scripts to execute whenever someone visits the page. This issue only affects WordPress websites that use multi-site setup or have the “unfiltered_html” setting disabled.

Detected in:

Login Screen Manager open vulnerable versions: >= * <= 3.5.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.