Input validation vulnerability in TM WooCommerce Compare & Wishlist 1.1.7

The TM WooCommerce Compare & Wishlist plugin for WordPress could be vulnerable to a type of attack known as Stored Cross-Site Scripting. This attack could be carried out by users with contributor-level permissions or higher. It involves injecting arbitrary web scripts into pages, which will be executed when any user accesses the page. Versions up to and including 1.1.7 of the plugin are affected due to insufficient input sanitization and output escaping on user supplied attributes.

Detected in:

TM WooCommerce Compare & Wishlist open vulnerable versions: >= * <= 1.1.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.