Input validation vulnerability in Icon Widget 1.3.0

The Icon Widget plugin for WordPress has a flaw that allows hackers to insert harmful code into pages using the plugin’s shortcodes. This can happen in all versions up to and including 1.3.0 because the plugin does not properly filter or protect against user input. As a result, attackers who have contributor-level or higher permissions can insert code that will be activated whenever someone views the page.

Detected in:

Icon Widget fixed vulnerable versions: >= * <= 1.3.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.