Input validation vulnerability in Suki Sites Import 1.2.1

A plugin called Suki Sites Import for WordPress has a security issue that makes it vulnerable to a type of cyber attack called Stored Cross-Site Scripting. This happens when someone uploads an SVG file, and the plugin doesn’t properly clean and protect the file’s content. This means that someone with the right permissions can sneak in harmful code that will run when anyone opens the SVG file.

Detected in:

Suki Sites Import open vulnerable versions: >= * <= 1.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.