Input validation vulnerability in WPCode – Insert Headers and Footers + Custom Code Snippets – WordPress Code Manager 2.0.13

The WPCode plugin for WordPress is not secure in versions up to, and including 2.0.13. An unauthenticated attacker can inject malicious web scripts into pages which will run when a user accesses the page. This is because the plugin does not filter or protect against malicious input and output.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.