Input validation vulnerability in WP Categories Widget 2.2

The WP Categories Widget plugin for WordPress is vulnerable to a type of malicious code injection called Reflected Cross-Site Scripting. Versions of the plugin up to and including 2.2 do not have the necessary security measures in place to protect against this type of attack. This means that unauthenticated attackers can inject malicious web scripts into pages, which will be executed when any user visits the page.

Detected in:

WP Categories Widget open vulnerable versions: >= * <= 2.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.