Input validation vulnerability in Meks Easy Ads Widget 2.0.8

The Meks Easy Ads Widget plugin for WordPress has a security issue called Stored Cross-Site Scripting. This can happen in versions 2.0.8 and lower because the plugin doesn’t properly clean up user input and output. This means that someone who has administrator access or higher could add harmful code to a page that would run whenever someone visits it. This only affects websites with multiple sub-sites or those that have disabled unfiltered_html.

Detected in:

Meks Easy Ads Widget fixed vulnerable versions: >= * <= 2.0.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.