Input validation vulnerability in Category SEO Meta Tags 2.5

The Category SEO Meta Tags plugin for WordPress is a tool to help website owners easily optimize their website for search engines. However, it has been found that all versions up to and including version 2.5 are vulnerable to an attack known as Stored Cross-Site Scripting. This type of attack allows an attacker with administrator-level permissions to inject malicious code into pages on the website. When a user visits the page, the code will execute, potentially stealing data or damaging the user’s computer. This only affects websites which have enabled multi-site features, or disabled the “unfiltered_html” feature.

Detected in:

Category SEO Meta Tags open vulnerable versions: >= * <= 2.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.