Input validation vulnerability in Widget Shortcode 0.3.5

. The Widget Shortcode plugin for WordPress can be exploited by attackers with contributor level permissions or higher. This would allow them to inject malicious web scripts into pages that will execute whenever a user visits an infected page. This vulnerability affects versions of the plugin up to and including 0.3.5 due to a lack of input sanitization and output escaping for user-provided attributes.

Detected in:

Widget Shortcode open vulnerable versions: >= * <= 0.3.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.