Input validation vulnerability in BSK PDF Manager 2.9

The BSK PDF Manager plugin for WordPress has a security flaw which allows attackers to inject malicious web scripts into pages. This vulnerability is present in versions 1.3 to 2.9 of the plugin. An attacker can do this if they are authenticated, which means they have already logged in. The malicious scripts will be executed every time a user visits one of the injected pages. This vulnerability is due to a lack of input sanitation and output escaping when the ‘cat_title’ parameter is used.

Detected in:

BSK PDF Manager open vulnerable versions: >= 1.3 <= 2.9

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.