WordPress.Security.ValidatedSanitizedInput.InputNotValidated

Input is not validated

Request data is used without checking that it is allowed for the operation.

critical weight

Why It Shows Up

The scan found input from a request superglobal being used without validation such as capability checks, allowlists, type checks, or range checks.

Why It Matters

Sanitization cleans a value, but validation proves the value is acceptable. Missing validation can allow unexpected actions, invalid states, or unsafe query choices.

How to Fix

  • Check that IDs are positive integers, enum-like values are in an allowlist, and URLs or file paths are constrained.
  • Pair state-changing requests with nonce and capability checks.
  • Reject or safely default values that do not pass validation.

Affected Plugins

RankPluginScoreErrorsWarningsInstallsAddedUpdatedTop Issue
#251Feed Them Social – Social Media Feeds, Video, and Photo Galleries2356353520k+Output is not escaped
#252Image Photo Gallery Final Tiles Grid235781,50220k+Non-prefixed global variable
#253Flexmls® IDX Plugin231,2689571k+Output is not escaped
#254Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder234,7461,27930k+Non Singular String Literal Domain
#255Front End PM239782,2645k+Non-prefixed global variable
#256Tracking and Consent Manager – WP Full Picture231,2803,2233k+Non-prefixed global variable
#257Fuse Social Floating Sidebar231,8401,57310k+Non-prefixed global variable
#258Futurio Extra2378720520k+Text Domain Mismatch
#259FV Flowplayer Video Player231,3111,45420k+Output is not escaped
#260GAinWP Google Analytics Integration for WordPress235251768k+Output is not escaped
#261GamiPress – Gamification plugin to reward points, achievements, badges & ranks in WordPress233,6622,97110k+Output is not escaped
#262The GDPR Framework By Data443231,28751710k+Short PHP open tag found
#263Gmedia Photo Gallery233501,1217k+Non-prefixed global variable
#264Interactive Content – H5P2356538040k+Non Singular String Literal Domain
#265Happy Addons for Elementor23573444400k+Output is not escaped
#266Hunk Companion232,5446876k+Text Domain Mismatch
#267Payment forms, Buy now buttons, and Invoicing System | GetPaid233701,2585k+Non-prefixed global variable
#268IP Geo Block233995899k+Output is not escaped
#269Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress2391693300k+Non-prefixed namespace
#270Justified Gallery235891,4179k+Non-prefixed global variable
#271Kadence Blocks — Page Builder Toolkit for Gutenberg Editor23552,127600k+Non-prefixed global variable
#272Kenta Companion236571,4192k+Non-prefixed global variable
#273King Addons for Elementor – 80+ Elementor Widgets, 4 000+ Elementor Templates, WooCommerce, Mega Menu, Popup Builder231,8373,87810k+Non-prefixed global variable
#274Masteriyo LMS – LMS Course Builder, Quizzes & Certificates231922,1235k+Non-prefixed global variable
#275License Manager for WooCommerce231298196k+Request data is not unslashed
#276Like Button Rating ♥ LikeBtn231,2316174k+Unsafe printing function
#277Link Whisper Free233,8825,30330k+Text Domain Mismatch
#278Custom Login Page Customizer236871,40890k+Non-prefixed global variable
#279Login With Ajax – Fast Logins, 2FA, Redirects2362352010k+Output is not escaped
#280Master Slider – Responsive Touch Slider2380040860k+Output is not escaped
#281MasterStudy LMS WordPress Plugin – for Online Courses and Education231,4194,87510k+Non-prefixed global variable
#282MaxButtons – Create buttons2365540970k+Output is not escaped
#283Media Library Assistant231,1443,94370k+Nonce verification recommended
#284MediaPress239045834k+Output is not escaped
#285Menu Image, Icons made easy235911,406100k+Non-prefixed global variable
#286MotoPress Appointment Booking232,3628572k+Text Domain Mismatch
#287MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar234,06548820k+Text Domain Mismatch
#288MStore API – Create Native Android & iOS Apps On The Cloud236187643k+SQL query is not prepared
#289MultiParcels Shipping For WooCommerce231773834k+Request data is not unslashed
#290MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO234885802k+Missing nonce verification
#291MyWorks Sync for WooCommerce & QuickBooks Online232,2929,1015k+Non-prefixed global variable
#292ND Shortcodes236212,42620k+Non-prefixed global variable
#293News Kit Addons For Elementor23654194k+Post Not In exclude
#294Next Active Directory Integration236832842k+Exception output is not escaped
#295Ninja Forms – The Contact Form Builder That Grows With You237541,525600k+Nonce verification recommended
#296NitroPack – Performance, Page Speed & Cache Plugin for Core Web Vitals, CDN & Image Optimization23315631100k+Output is not escaped
#297Ocean Extra231,4942,106500k+Non-prefixed global variable
#298Issues and Series for Newspapers, Magazines, Publishers, Writers233467102k+Nonce verification recommended
#299Patchstack – WordPress & Plugins Security2310748940k+Missing nonce verification
#300Photo Gallery by 10Web – Mobile-Friendly Image Gallery234,1591,553100k+Output is not escaped