Input validation vulnerability in Breakdance 1.7.1

The Breakdance plugin for WordPress has a security issue that allows anyone using version 1.7.1 or earlier to execute code on the website through post meta data. This is because the plugin saves custom information without using an underscore prefix. This means that even users with lower permissions, like contributors, can change this data and potentially gain more access or run code on the site.

Detected in:

Breakdance fixed vulnerable versions: >= * <= 1.7.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.