Input validation vulnerability in Eventbee RSVP Widget 1.0

The Eventbee RSVP Widget plugin for WordPress has a security issue that allows unauthorized individuals to insert harmful code into web pages. This can occur in versions 1.0 and below, as the plugin does not properly clean and protect input and output. This means that hackers with contributor or higher access can inject harmful scripts into pages, which will then run whenever a user visits the affected page.

Detected in:

Eventbee RSVP Widget open vulnerable versions: >= * <= 1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.