Input validation vulnerability in WP Flow Plus 5.2.2

The WP Flow Plus plugin for WordPress has a security flaw that allows attackers to inject harmful code into pages using a specific shortcode. This can happen in all versions of the plugin, including version 5.2.2, because the plugin does not properly clean and protect user input. This means that attackers who have contributor-level access or higher can insert their own code into pages, which will then run when a user visits that page.

Detected in:

WP Flow Plus fixed vulnerable versions: >= * <= 5.2.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.