Input validation vulnerability in Popup with fancybox 3.5

The Popup with fancybox plugin for WordPress is vulnerable to an attack called SQL Injection. This type of attack is made possible because the plugin doesn’t properly escape user-supplied data and doesn’t properly prepare the existing SQL query. This makes it possible for attackers with subscriber-level permissions or higher to add extra queries into the existing ones that can be used to get sensitive information from the database.

Detected in:

Popup with fancybox fixed vulnerable versions: >= * <= 3.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.