Input validation vulnerability in Blog Filter – Advanced Post Filtering with Categories Or Tags, Post Portfolio Gallery, Blog Design Template, Post Layout 1.5.3

The Blog Filter plugin for WordPress is not secure in versions up to and including 1.5.3. This plugin is vulnerable to a type of attack called Stored Cross-Site Scripting. This type of attack is possible when authenticated attackers with contributor-level (or higher) permissions can inject malicious web scripts into pages, which will then execute when a user accesses the page. This can be prevented if there is proper input sanitization and output escaping of user-supplied attributes.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.