Input validation vulnerability in Elements Plus! 2.16.4

The Elements Plus! plugin for WordPress is at risk for a type of cyber attack called Stored Cross-Site Scripting. This can happen through the plugin’s Image Comparison, HotSpot Plus, and Google Maps widgets in versions 2.16.4 and below. The problem is that the plugin doesn’t properly clean or protect user-submitted information, which allows attackers with certain levels of access to insert their own malicious code into web pages. This code can then run whenever someone visits the infected page.

Detected in:

Elements Plus! open vulnerable versions: >= * <= 2.16.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.