Input validation vulnerability in The Tribal Plugin 1.3.3

The Tribal plugin for WordPress has a security issue called Stored Cross-Site Scripting. This can happen in versions 1.3.3 and below because the plugin does not properly clean up the input and output. This means that someone with high-level access to the website can insert harmful code into pages, which will run whenever someone visits that page. This only affects websites with multiple sites or websites that have disabled the option for unfiltered HTML.

Detected in:

The Tribal Plugin fixed vulnerable versions: >= * <= 1.3.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.