Input validation vulnerability in Ultimate Instagram Feed – WordPress Plugin 1.3

The Ultimate Instagram Feed – WordPress Plugin for WordPress has an issue that could allow an unauthenticated attacker to inject malicious web scripts into pages that are viewed by other users. This issue affects versions up to and including 1.3, and is caused by the plugin not properly sanitizing user input in the ‘url’ parameter, or not properly escaping its output. If a user is tricked into performing an action, such as clicking on a link, these malicious scripts could be executed.

Detected in:

Ultimate Instagram Feed – WordPress Plugin open vulnerable versions: >= * <= 1.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.