Input validation vulnerability in EG-Series 2.1.1

The EG-Series plugin for WordPress has a security vulnerability that allows attackers to inject harmful code through the [series] shortcode. This can happen on any version of the plugin up to 2.1.1. The issue is caused by not properly checking and protecting user input in the shortcode_title function. As a result, attackers who have contributor-level access or higher and have the Classic Editor plugin enabled can add malicious JavaScript code to the titletag attribute, which will run whenever someone views the affected page.

Detected in:

EG-Series fixed vulnerable versions: >= * <= 2.1.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.