Input validation vulnerability in Template Kit – Import 1.0.14

The Template Kit – Import plugin for WordPress has a security issue where it can be attacked by malicious code through the template upload function. This can happen in any version up to 1.0.14 because it doesn’t properly protect against harmful input and output. As a result, attackers who are logged in with author or higher access can insert their own web scripts into pages. These scripts will then run whenever a user visits the affected page.

Detected in:

Template Kit – Import fixed vulnerable versions: >= * <= 1.0.14

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.