Input validation vulnerability in wp-pano 1.17

The wp-pano plugin used for WordPress has a security issue known as Stored Cross-Site Scripting. This problem occurs in versions 1.17 and below because the plugin does not properly clean up input data or protect against malicious code. This means that someone with contributor-level access or higher can insert harmful scripts into pages, which will then run whenever someone views the affected page.

Detected in:

wp-pano open vulnerable versions: >= * <= 1.17

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.