Input validation vulnerability in Blog, Posts and Category Filter for Elementor 1.0.3

The Blog, Posts and Category Filter for Elementor plugin for WordPress has a security issue that allows attackers to inject harmful code into web pages. This vulnerability is present in all versions up to 1.0.3 and is caused by not properly filtering and escaping input from the ‘post_types’ attribute. This means that attackers with contributor-level access or higher can add code to pages that will run when someone views it.

Detected in:

Blog, Posts and Category Filter for Elementor fixed vulnerable versions: >= * <= 1.0.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.