Access violation vulnerability in BuddyPress Xprofile Custom Fields Type 2.6.3

The BuddyPress Xprofile Custom Fields Type plugin for WordPress has a security vulnerability that could allow an attacker with some level of access to the WordPress website to delete files, like wp-config.php. This vulnerability exists in versions up to and including 2.6.3 and is caused by the plugin not properly sanitizing and escaping user input. It is recommended that users of the plugin update to the latest version of the plugin to ensure their site is secure.

Detected in:

BuddyPress Xprofile Custom Fields Type open vulnerable versions: >= * <= 2.6.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.