Input validation vulnerability in custom-metas 1.5.1

The Custom Metas plugin for WordPress is vulnerable to a type of attack called Reflected Cross-Site Scripting. This means that it is possible for malicious actors to inject malicious code into webpages that an authenticated user may visit. This is due to the plugin not being able to properly sanitize user input and escape output. The vulnerable versions of the plugin are 1.5.1 and older.

Detected in:

custom-metas open vulnerable versions: >= * <= 1.5.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.