Input validation vulnerability in WPKoi Templates for Elementor 2.5.9

The WPKoi Templates for Elementor plugin for WordPress has a security issue that allows attackers to inject harmful web scripts into pages. This can happen when certain parameters, such as ‘id’ and ‘mixColor’, are not properly sanitized and escaped. This vulnerability affects all versions up to and including 2.5.9, and can be exploited by authenticated attackers with Contributor-level access or higher.

Detected in:

WPKoi Templates for Elementor fixed vulnerable versions: >= * <= 2.5.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.