Input validation vulnerability in Exchange Rates 1.2.5

The Exchange Rates plugin for WordPress has a security issue that makes it vulnerable to a type of attack called Stored Cross-Site Scripting. This can happen in versions 1.2.5 and below because the plugin doesn’t properly clean and protect the information it receives and displays. This means that someone who has the ability to log into the website and has contributor-level access or higher, can insert harmful code into a page that will run whenever someone visits that page.

Detected in:

Exchange Rates fixed vulnerable versions: >= * <= 1.2.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.