Input validation vulnerability in Xavin's List Subpages 1.3

The Xavin’s List Subpages plugin for WordPress is not secure and can be easily hacked. This is because the plugin does not properly protect against malicious code that can be added through the ‘xls’ shortcode. Attackers who have contributor-level access or higher can easily add harmful scripts to pages, which will automatically run when a user visits the page.

Detected in:

Xavin's List Subpages open vulnerable versions: >= * <= 1.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.