Input validation vulnerability in Built-in Widgets Query extend (Custom Post Types & more) 1.05

The Built-in Widgets Query extend plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting. This type of attack occurs when a malicious link or script can be added to a web page to be executed when someone clicks on it. Versions of the plugin up to and including 1.05 are vulnerable due to the insufficient input sanitization and output escaping. This means that unauthenticated attackers can inject malicious code into pages via a URL if they can trick a user into clicking on it.

Detected in:

Built-in Widgets Query extend (Custom Post Types & more) fixed vulnerable versions: >= * <= 1.05

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.