Input validation vulnerability in ColorMag 3.1.6

The ColorMag theme for WordPress has a security issue called Stored Cross-Site Scripting. This means that a person’s Display Name can be used to insert malicious web scripts into pages. This can happen in all versions of the theme, including the latest one (3.1.6). This vulnerability is caused by not properly checking and filtering input and output, which can allow attackers with contributor-level access or higher to inject harmful code into pages that will be executed when a user visits the page.

Detected in:

ColorMag fixed vulnerable versions: >= * <= 3.1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.