Input validation vulnerability in Canva – Design beautiful blog graphics 1.2.4

The Canva plugin, which helps to create attractive blog graphics on WordPress, has a security issue. This vulnerability, known as Reflected Cross-Site Scripting, affects all versions of the plugin up to 1.2.4. This means that the plugin does not properly check and remove harmful code from user input, allowing attackers to insert their own malicious scripts into web pages. This can happen if they can trick a user into clicking on a link.

Detected in:

Canva – Design beautiful blog graphics open vulnerable versions: >= * <= 1.2.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.