Input validation vulnerability in WP Matterport Shortcode 2.1.5

The WordPress Matterport Shortcode plugin contains a security flaw that could let an unauthenticated attacker inject malicious web scripts into pages. This security flaw exists in all versions of the plugin up to and including version 2.1.5 because of the lack of input sanitization and output escaping. To exploit this vulnerability, the attacker must be able to trick a user into performing an action, such as clicking on a link.

Detected in:

Matterport Shortcode fixed vulnerable versions:
WP Matterport Shortcode open vulnerable versions: >= * <= 2.1.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.