Input validation vulnerability in Bulk Me Now! 2.0

The Bulk Me Now! plugin for WordPress has a security issue that allows malicious code to be injected into pages. This can happen if someone with certain access levels uses the plugin’s ‘bmn’ shortcode. The plugin is vulnerable in all versions up to and including 2.0 because it does not properly clean and protect user input. This means that an attacker who is logged in and has contributor-level access or higher can insert harmful scripts into pages that will run when a user visits that page.

Detected in:

Bulk Me Now! open vulnerable versions: >= * <= 2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.