Input validation vulnerability in Meteor Slides 1.5.7

The Meteor Slides plugin used in WordPress can be hacked through a vulnerability called Stored Cross-Site Scripting. This problem affects versions 1.5.7 and below because the plugin does not properly clean up input and output. This allows attackers who have administrator-level access to insert their own harmful scripts into pages, which will then be executed when someone views the infected page. This only affects sites with multiple installations and sites where a security feature called unfiltered_html has been turned off.

Detected in:

Meteor Slides open vulnerable versions: >= * <= 1.5.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.