Input validation vulnerability in Anchor Episodes Index (Spotify for Podcasters) 2.1.8

The Anchor Episodes Index (Spotify for Podcasters) plugin for WordPress is vulnerable to a type of attack called Stored Cross-Site Scripting, which can allow those with contributor-level privileges or higher to inject malicious scripts into pages on the WordPress website. These malicious scripts can then be triggered whenever a user visits the page. This vulnerability affects all versions of the plugin up to and including version 2.1.7 because it does not properly sanitize and escape user supplied attributes.

Detected in:

Anchor Episodes Index (Spotify for Podcasters) fixed vulnerable versions: >= * < 2.1.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.