Input validation vulnerability in Sermon'e – Sermons Online 1.0.0

The Sermon’e plugin for WordPress is not secure against malicious attacks in its versions up to and including 1.0.0. If you are running one of these versions, attackers with contributor-level or higher permissions can inject web scripts into pages, which will execute when a user views the page. This is possible because the plugin does not properly check user input and does not escape output.

Detected in:

Sermon'e – Sermons Online open vulnerable versions: > 0 < 0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.