Input validation vulnerability in Ultimate Push Notifications ( Mobile / Desktop ), Receive Notification From WooCommerce, BuddyPress, WordPress Default Events & Many More 1.1.8

The plugin called “Ultimate Push Notifications” for WordPress has a security problem called SQL Injection. This affects versions 1.1.8 and below. This issue is caused by not properly protecting the user’s input and not properly preparing the existing SQL query. This means that attackers who are logged in with subscriber or higher level access can add their own SQL queries to the existing ones and gain access to private information from the database.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.