Input validation vulnerability in Ultimate Product Catalog 5.2.5

The Ultimate Product Catalog plugin for WordPress is vulnerable to a type of security threat called Stored Cross-Site Scripting. This type of threat is present in versions 5.2.5 and earlier of the plugin. It could let attackers with administrator-level permissions or higher inject malicious web scripts into pages on the website. These scripts could be executed whenever users access the affected pages. This type of vulnerability only affects WordPress websites that have multi-site installations or have disabled a security setting called ‘unfiltered_html’.

Detected in:

Ultimate Product Catalog fixed vulnerable versions: >= * <= 5.2.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.