Input validation vulnerability in Download buttons for Youtube videos 1.03

The Download buttons for Youtube videos plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting in versions up to 1.03. This type of attack is possible because the plugin does not properly check or protect the input it receives through URLs, and does not properly escape the output it provides. This means that if an attacker can trick someone into clicking on a malicious link, it is possible for them to inject malicious code into pages.

Detected in:

Download buttons for Youtube videos fixed vulnerable versions: >= * <= 1.03

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.