Input validation vulnerability in Blocksy Companion 2.0.45

The Blocksy Companion plugin for WordPress is at risk of being hacked through a type of attack called Stored Cross-Site Scripting. This can happen when someone uploads a certain type of file, called an SVG, to the plugin. This vulnerability affects versions 2.0.45 and earlier because the plugin does not properly check and secure the input and output of information. As a result, attackers who are logged in to the website with at least contributor-level permissions can add harmful code to pages that will run when someone visits that page.

Detected in:

Blocksy Companion fixed vulnerable versions: >= * <= 2.0.45

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.