Input validation vulnerability in Ptengine – Heatmap Analytics 1.0.2

The Ptengine – Heatmap Analytics plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting. This vulnerability is present in all versions of the plugin before version 1.0.2. This attack allows unauthenticated attackers to inject malicious web scripts into pages. These scripts can be executed if a user clicks on a link that the attacker created. To protect yourself from this vulnerability, make sure you have updated the plugin to version 1.0.2 or later.

Detected in:

Ptengine – Heatmap Analytics open vulnerable versions: >= * < 1.0.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.