Input validation vulnerability in Custom Base Terms 1.0.2.3

The Custom Base Terms plugin for WordPress is not secure in versions up to and including 1.0.2.3. This vulnerability can let an attacker who has administrator-level permissions to inject malicious web scripts into pages on your website. This would then make it possible for these scripts to run when any user visits the page. This is only a risk if you have a multi-site installation or if you have disabled the feature called ‘unfiltered_html’.

Detected in:

Custom Base Terms fixed vulnerable versions: >= * <= 1.0.2.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.