Input validation vulnerability in PCRecruiter Extensions 1.4.10

The PCRecruiter Extensions plugin for WordPress has a security issue called Stored Cross-Site Scripting. This means that hackers can insert harmful code into the plugin’s ‘PCRecruiter’ feature, which could affect all versions up to and including 1.4.10. This can happen because the plugin doesn’t properly check and protect user-provided information. As a result, attackers with at least contributor-level access can add their own code to pages that will run when someone visits that page.

Detected in:

PCRecruiter Extensions fixed vulnerable versions: >= * <= 1.4.22

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.