Input validation vulnerability in Bamazoo – Button Generator 1.0

The Bamazoo – Button Generator plugin for WordPress has a security vulnerability known as Stored Cross-Site Scripting. This means that the plugin’s dgs shortcode does not properly clean the information that users provide and can allow attackers to insert harmful code into pages. This can happen when a user with contributor-level access or higher injects a web script, which will then run whenever someone views that page.

Detected in:

Bamazoo – Button Generator open vulnerable versions: >= * <= 1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.