Input validation vulnerability in ConvertPlug 3.5.25

The ConvertPlug plugin for WordPress has a security issue that allows attackers to inject harmful code through a feature called ‘smile_info_bar’. This can only be done by someone who has access to the website as a contributor or higher. If the website has other plugins or themes that also have security issues, the attacker may be able to delete files, access private information, or run their own code.

Detected in:

ConvertPlus fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.