Input validation vulnerability in Get Custom Field Values 4.1

The Get Custom Field Values plugin for WordPress has a security vulnerability that could allow an attacker with contributor-level or higher permissions to insert malicious web scripts onto pages that would run when any user accessed the page. This vulnerability exists in versions of the plugin up to, and including, 4.0.1, because the plugin does not properly sanitize and escape user input.

Detected in:

Get Custom Field Values fixed vulnerable versions: >= * < 4.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.