Input validation vulnerability in Alma – Pay in installments or later for WooCommerce 5.1.3

The Alma – Pay in Installments or Later for WooCommerce plugin for WordPress has a vulnerability that could allow attackers with contributor-level access or higher to inject malicious web scripts into pages. These scripts will then be executed every time someone visits the page. This vulnerability is present in versions up to and including 5.1.3 due to a lack of proper input sanitization and output escaping.

Detected in:

Alma – Pay in installments or later for WooCommerce open vulnerable versions: >= * <= 5.2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.