Input validation vulnerability in Organization chart 1.5.0

The Organization chart plugin for WordPress has a security vulnerability that allows attackers to insert harmful code into website pages. This can be done by exploiting the ‘title_input’ and ‘node_description’ parameters. This vulnerability affects all versions up to 1.5.0 and is caused by inadequate protection of user input and output. While normally only administrators can exploit this, subscribers can also be given permission to use and configure charts.

Detected in:

Organization chart fixed vulnerable versions: >= * <= 1.5.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.