Input validation vulnerability in CodePen Embedded Pens Shortcode 1.0.0

The plugin called CodePen Embedded Pens Shortcode for WordPress has a security issue. This issue, called Stored Cross-Site Scripting, can be found in versions 1.0.0 and below. This is because the plugin does not properly clean and protect the information that is input and output. This means that attackers who have contributor access or higher can add harmful scripts to pages that will run when a user opens the page.

Detected in:

CodePen Embedded Pens Shortcode fixed vulnerable versions: >= * <= 1.0.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.