Input validation vulnerability in WishSuite – Wishlist for WooCommerce 1.3.4

The WishSuite plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting. This type of attack can happen if the plugin is running an outdated version, up to and including 1.3.4. This type of attack is possible because the plugin is not properly checking and blocking the data it receives. If an attacker with administrator-level access is able to inject malicious data into the plugin, the malicious code will be executed when someone visits a page with the malicious code. This type of attack is only possible if the website is a multi-site installation, or the website has disabled the security setting called ‘unfiltered_html’.

Detected in:

WishSuite – Wishlist for WooCommerce fixed vulnerable versions: >= * <= 1.3.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.