Input validation vulnerability in MakeStories (for Google Web Stories) 2.6.4

The MakeStories plugin for WordPress, used to make web stories, is vulnerable to a form of attack called Cross-Site Scripting. This means that someone could inject malicious scripts into the plugin which would then execute in the victim’s browser. This vulnerability exists in all versions of the plugin up to and including version 2.6.4. The issue is caused by not properly sanitizing input data and not properly escaping output.

Detected in:

MakeStories (for Google Web Stories) open vulnerable versions: >= * <= 2.6.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.