Input validation vulnerability in AN_GradeBook 5.0.1

The AN_GradeBook plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting. This is because the plugin does not properly secure its settings from unauthorized input and output. If an attacker with administrator-level permissions or higher is able to get access to the plugin’s settings, they can inject malicious code into pages that will run whenever someone views the page. This vulnerability only affects WordPress websites that have multiple sites or have disabled a certain feature called “unfiltered_html”.

Detected in:

GradeBook fixed vulnerable versions:
AN_GradeBook open vulnerable versions: >= * <= 5.0.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.