Input validation vulnerability in QR Twitter Widget 0.2.3

The QR Twitter Widget plugin for WordPress may be vulnerable to a type of attack called Stored Cross-Site Scripting. This type of attack can allow someone with an account on the website that uses the plugin to inject malicious code into pages that can be executed when other users view them. The vulnerability exists in versions of the plugin up to and including 0.2.3. This is because the plugin does not properly check the input or escape the output.

Detected in:

QR Twitter Widget open vulnerable versions: >= * <= 0.2.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.