Input validation vulnerability in BZScore – Live Score 1.03

The BZScore – Live Score plugin for WordPress has a security vulnerability which allows users with contributor-level or higher permissions to inject malicious web scripts into pages on the website. This could cause those pages to execute malicious code when someone visits them. This vulnerability is present in all versions up to and including version 1.03 due to the plugin not properly sanitizing user inputs or escaping outputs.

Detected in:

BZScore – Live Score fixed vulnerable versions: >= * <= 1.03

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.