Input validation vulnerability in Carrrot 1.1.0

The Carrot plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting, and it affects versions up to and including 1.1.0. This attack can be done by people who have administrator-level access or higher, and it allows them to inject web scripts into pages. These scripts will run whenever someone visits the page they were injected into. This vulnerability only applies to WordPress multi-site installations, and installations where unfiltered_html has been disabled.

Detected in:

Carrrot open vulnerable versions: >= * <= 1.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.