Input validation vulnerability in Include Me 1.3.2

The Include Me plugin for WordPress has a problem where it can be attacked by harmful scripts. This can happen in versions 1.3.2 and below because it doesn’t properly clean up the information it receives and sends out. This means that people who have high-level access to the website can add their own scripts to pages that will run when someone visits those pages. This only affects websites with multiple sites or websites that have turned off a security feature called unfiltered_html.

Detected in:

Include Me fixed vulnerable versions: >= * <= 1.3.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.