Invite Anyone <= 1.3.15 - Improper Input Validation

2017-03-22 00:00
Anonymous

Strategic Overview

Status
Patched in 1.3.16
Affected PluginInvite Anyone
Affected Version<= 1.3.15
CVSS7.5High
CVECVE-2017-18545
View all Invite Anyone vulnerabilities

Vulnerability Overview

The invite-anyone plugin before 1.3.16 for WordPress has incorrect escaping of untrusted Dashboard and front-end input.

Technical Analysis

REMEDIATION: Update to version 1.3.16, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C