Input validation vulnerability in salient-core 2.0.2

The Salient Core plugin for WordPress is vulnerable to a type of cyber attack known as ‘Stored Cross-Site Scripting’. This means that people with certain levels of access in the plugin, such as contributors, can insert harmful code into pages which will be executed when someone visits those pages. All versions of the plugin up to version 2.0.2 are vulnerable to this attack. This is because the plugin doesn’t take enough precautions to protect user data and to make sure the code being inserted is safe.

Detected in:

salient-core fixed vulnerable versions: >= * <= 2.0.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.