Input validation vulnerability in OpenSheetMusicDisplay 1.4.0

A plugin called OpenSheetMusicDisplay used in WordPress has a security issue where attackers can insert harmful web scripts into pages. This can happen if the ‘className’ parameter is not properly checked and sanitized. It affects all versions up to 1.4.0 and can be done by someone with Contributor-level access or higher.

Detected in:

OpenSheetMusicDisplay fixed vulnerable versions: >= * <= 1.4.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.