Input validation vulnerability in Mail Control – Email Customizer, SMTP Deliverability, logging, open and click Tracking 0.2.8

The Mail Control plugin for WordPress is not secure in versions up to 0.2.8. Someone who is not logged in can put malicious web scripts in pages, which will run when someone visits one of these pages. This is possible because the plugin does not properly check the inputs or protect the outputs from these scripts.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.