Input validation vulnerability in NinjaTeam Chat for Telegram 1.1

The NinjaTeam Chat for Telegram plugin for WordPress has a security vulnerability called Stored Cross-Site Scripting. This means that the ‘username’ parameter is not properly checked for harmful code, allowing attackers with certain levels of access to inject harmful code into pages that will run when a user opens the page.

Detected in:

NinjaTeam Chat for Telegram fixed vulnerable versions: >= * <= 1.1
WP Telegram Chat Widget fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.