Input validation vulnerability in EZ SQL Reports Shortcode Widget and DB Backup 5.25.11

A plugin for WordPress called EZ SQL Reports Shortcode Widget and DB Backup has a security issue. This problem is called Stored Cross-Site Scripting and it affects all versions up to 5.25.11. The plugin does not properly clean up the code that users enter, so attackers with certain permissions can add their own harmful code to a page. This code will run whenever someone views the page.

Detected in:

EZ SQL Reports Shortcode Widget and DB Backup fixed vulnerable versions: >= * <= 5.25.11

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.