Input validation vulnerability in Power BI Embedded for WordPress 1.1.3

The Power BI Embedded for WordPress plugin is vulnerable to an attack called Stored Cross-Site Scripting. This attack can be done by editing the ‘_power_bi_width’ and ‘_power_bi_height’ parameters on the ‘Edit Power BI’ page. This type of attack can be done by anyone with contributor level permissions or higher on versions of the plugin up to and including 1.1.3. It allows attackers to inject malicious web scripts into pages which will be executed every time someone visits the page.

Detected in:

Power BI Embedded for WordPress open vulnerable versions: >= 1.1.3 <= 1.1.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.