Input validation vulnerability in Ultimate Product Catalog 3.1.3

The Ultimate Product Catalogue for WordPress is a tool used to organize and display product information on websites. Unfortunately, versions of the software prior to 3.1.3 have a security vulnerability that can be exploited by unauthenticated attackers. This vulnerability is caused by the software not properly protecting user supplied parameters, and not properly preparing existing SQL queries. This allows attackers to add additional SQL queries to the existing queries, which can be used to get sensitive data from the database. It is important to update to the latest version of the software to prevent this vulnerability.

Detected in:

Ultimate Product Catalog fixed vulnerable versions: >= * < 3.1.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.