Input validation vulnerability in Featured Posts by BestWebSoft 1.0.1

The Featured Posts by BestWebSoft plugin for WordPress had a security issue in versions before 1.0.1 that allowed an unauthenticated attacker to inject malicious web scripts into pages. This was caused by the plugin not properly sanitizing and escaping user input, specifically the ‘category’ parameter. If a malicious link was clicked, the scripts would be executed. To protect against this, users should ensure they are using version 1.0.1 or later of the plugin.

Detected in:

Featured Posts by BestWebSoft open vulnerable versions: >= * < 1.0.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.