Input validation vulnerability in Comment Reply Email 1.0.3

The Comment Reply Email WordPress plugin has a security issue in versions 1.0.3 and lower. A user with administrator privileges can inject their own web scripts into pages on the website. If someone visits the injected page, the malicious script will execute. This vulnerability only affects multi-site installations and installations that have disabled a feature called unfiltered_html.

Detected in:

Comment Reply Email fixed vulnerable versions: >= * <= 1.0.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.