Input validation vulnerability in WpF Ultimate Carousel 1.0.11

The WpF Ultimate Carousel plugin for WordPress can be attacked by hackers through a vulnerability known as Stored Cross-Site Scripting. This can happen in versions 1.0.11 and below because the plugin does not properly clean and secure the input and output of information. This means that attackers who have contributor-level access or above can insert harmful scripts into web pages. These scripts will then run whenever someone accesses the affected page.

Detected in:

WpF Ultimate Carousel open vulnerable versions: >= * <= 1.0.11

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.