Input validation vulnerability in Buy Me a Coffee – Button and Widget Plugin 3.6

The Buy Me a Coffee – Button and Widget Plugin for WordPress has a security vulnerability that could allow someone with administrator-level permissions on a multi-site installation or an installation where unfiltered_html has been disabled to inject malicious code into pages which will then be run whenever someone accesses that page. The vulnerability affects versions up to and including 3.6 of the plugin and is due to inadequate protection against malicious code being inputted and outputted.

Detected in:

Buy Me a Coffee – Button and Widget Plugin open vulnerable versions: >= * <= 3.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.