Input validation vulnerability in News Ticker Widget for Elementor 1.3.2

The News Ticker Widget for Elementor is a plugin for WordPress that displays a scrolling news ticker on a website. However, versions up to and including 1.3.2 have a security vulnerability called Stored Cross-Site Scripting. This means that the plugin does not properly filter or protect user input, allowing attackers with certain levels of access to inject harmful code into pages. This code could then be executed whenever a user visits the affected page.

Detected in:

News Ticker Widget for Elementor fixed vulnerable versions: >= * <= 1.3.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.