Input validation vulnerability in Wordfence Security – Firewall, Malware Scan, and Login Security 5.2.3

The Wordfence Security plugin for WordPress is vulnerable to a type of cyber attack called Stored Cross-Site Scripting. This type of attack happens when a user of the plugin, which is up to version 5.2.3, does not properly secure their webpages by sanitizing input and escaping output. This makes it possible for an unauthorized attacker to insert malicious web scripts into webpages that will execute malicious code whenever a user visits the page.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.