Input validation vulnerability in Pinterest RSS Widget 2.3.1

The Pinterest RSS Widget plugin for WordPress is vulnerable to a security issue called Stored Cross-Site Scripting. This is when a malicious user can inject malicious code into a page which can cause harm when another user accesses that page. This vulnerability affects versions of the plugin up to and including 2.3.1. Contributors or users with higher levels of access can inject this code into a page.

Detected in:

Pinterest RSS Widget open vulnerable versions: >= * <= 2.3.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.