Input validation vulnerability in bpmn.io 1.0

A popular plugin for WordPress called bpmn.io has a security issue that could allow hackers to inject harmful code into web pages. This can happen because the plugin doesn’t properly clean up user input and output. Attackers who have contributor or higher access can take advantage of this vulnerability and potentially run their own code whenever a user visits a page with the injected code.

Detected in:

bpmn.io open vulnerable versions: >= * <= 1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.