Input validation vulnerability in WP LESS to CSS 1.0

The WP LESS to CSS plugin for WordPress is vulnerable to a type of cyber attack known as Stored Cross-Site Scripting in versions up to 1.0. This type of attack can be used by an attacker with administrative level permissions to inject malicious code into pages on the website. This malicious code can then be executed by any user who visits the page. This vulnerability only affects WordPress websites with multiple sites and sites where HTML filtering has been disabled.

Detected in:

WP LESS to CSS open vulnerable versions: >= * <= 1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.