Input validation vulnerability in WP Abstracts 2.6.2

The WP Abstracts plugin for WordPress is vulnerable to a type of malicious attack, known as Stored Cross-Site Scripting, in versions up to and including 2.6.2. This type of attack is possible because the plugin does not properly check and filter the data it receives, or protect it when it is displayed. This means that an attacker, who has administrator-level access, could inject malicious web scripts into pages. These scripts would then run whenever a user views one of these pages. This vulnerability only affects multi-site installations and installations where a certain security setting, called unfiltered_html, has been disabled.

Detected in:

WP Abstracts open vulnerable versions: >= * <= 2.6.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.