Input validation vulnerability in Algori PDF Viewer 1.0.7

The Algori PDF Viewer add-on for WordPress has a security issue called Stored Cross-Site Scripting. This is because it uses an unsafe version of pdf.js in all versions, including 1.0.7. The problem is caused by not properly checking and formatting user input and output. This means that someone who is logged in and has author or higher permission could add harmful code to a page, which would run whenever anyone views that page.

Detected in:

Algori PDF Viewer fixed vulnerable versions: >= * <= 1.0.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.