Input validation vulnerability in Inline Click To Tweet 1.0.0

The plugin called “Inline Click To Tweet” used for WordPress has a security issue. This issue is called Stored Cross-Site Scripting and it affects versions 1.0.0 and below. This is because the plugin does not properly clean up the input and output of data. This vulnerability allows attackers who are logged in with contributor-level access or higher to add harmful web scripts to pages. These scripts will run whenever a user visits the page that has the injected script.

Detected in:

Inline Click To Tweet open vulnerable versions: >= * <= 1.0.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.