Input validation vulnerability in Institutions Directory 1.3.3

The WordPress plugin called Institutions Directory is currently at risk of being attacked by a type of cyber attack called Reflected Cross-Site Scripting. This can happen in all versions up to and including 1.3.3 because the plugin does not properly check and filter the information that users input, and it also does not properly protect against harmful scripts being displayed on the page. This means that someone who is not logged in or authenticated can potentially insert dangerous web scripts on a page if they can trick a user into clicking on a link.

Detected in:

Institutions Directory fixed vulnerable versions: >= * <= 1.3.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.