Input validation vulnerability in Spare – Ultimate MultiPurpose LESS Theme 1.7

The Spare theme for WordPress, called Ultimate MultiPurpose LESS Theme, has a security vulnerability that allows for Reflected Cross-Site Scripting. This means that in versions 1.7 and below, the theme does not properly filter or escape user input, making it possible for attackers to inject malicious scripts into web pages. This could happen if a user is tricked into clicking on a link.

Detected in:

Spare - Ultimate MultiPurpose LESS Theme open vulnerable versions: >= * <= 1.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.