Input validation vulnerability in Rotating Tweets (Twitter widget and shortcode) 1.9.10

The Rotating Tweets plugin for WordPress has a security issue that can allow attackers to inject harmful code into web pages. This can happen when a user with certain access levels uses the plugin’s ‘rotatingtweets’ feature. The plugin is vulnerable in all versions up to 1.9.10 because it doesn’t properly clean up user input and output. This means that users who are logged in and have contributor-level access or higher could potentially cause web scripts to run when other users visit the affected pages.

Detected in:

Rotating Tweets (Twitter widget and shortcode) open vulnerable versions: >= * <= 1.9.10

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.