Input validation vulnerability in Get Custom Field Values 4.0.1

The Get Custom Field Values plugin for WordPress is vulnerable to a security issue known as Stored Cross-Site Scripting. This is a type of attack that can be used to inject malicious code into web pages. This issue affects versions of the plugin up to and including the 4.0.1 version. It can be exploited by attackers who have administrator-level access to a WordPress site and can only be used on multi-site installations or sites where the ability to add HTML code has been disabled.

Detected in:

Get Custom Field Values fixed vulnerable versions: >= * <= 4.0.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.