Input validation vulnerability in WP Discord Invite 2.5.1

The WP Discord Invite plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting. This type of attack occurs when a website is not properly protected against malicious code. In this case, all versions of the plugin up to version 2.5.1 are affected because they do not have the necessary safeguards in place to stop attackers from injecting malicious code. This vulnerability is only present in multi-site installations and installations where unfiltered_html has been disabled. Attackers with administrator-level permissions and above can inject web scripts into pages that will execute whenever a user accesses the page. To protect against this type of attack, it is important to ensure that all versions of the WP Discord Invite plugin are up to date and that all websites are properly protected against malicious code.

Detected in:

WP Discord Invite open vulnerable versions: >= * <= 2.5.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.