Input validation vulnerability in Medialist 1.4.0

The Medialist plugin for WordPress is vulnerable to a type of security attack known as Stored Cross-Site Scripting through its shortcode(s) in all versions up to version 1.4.0. This means that users with contributor-level permissions or higher can inject malicious web scripts onto pages that will execute when any user accesses that page. This is possible because the plugin does not properly sanitize user input and does not properly protect the output.

Detected in:

Medialist fixed vulnerable versions: >= * <= 1.4.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.