Input validation vulnerability in Login Configurator 2.1

The Login Configurator plugin for WordPress is vulnerable to an attack called Reflected Cross-Site Scripting in versions 2.1 and lower. This plugin does not properly sanitize user input or protect output, which makes it possible for attackers to insert malicious web scripts into pages. If a user clicks on a link or performs an action that attackers have set up, the scripts can be executed.

Detected in:

Login Configurator open vulnerable versions: >= * <= 2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.