N/A
2026-03-20< 1.3.0
Injection Guard <= 1.2.9 - Unauthenticated Stored Cross-Site Scripting via Query Parameter Name
Minimum safe version
1.3.0
Update to 1.3.0 or later to address 5 fixable vulnerabilities
Injection Guard <= 1.2.9 - Unauthenticated Stored Cross-Site Scripting via Query Parameter Name
WordPress Injection Guard Plugin < 1.2.8 is vulnerable to Cross Site Scripting (XSS)
Injection Guard <= 1.2.1 - Missing Authorization to Whitelist Update
CVE-2023-32574
Injection Guard <= 1.2.1 - Cross-Site Request Forgery to Whitelist Update