Input validation vulnerability in Most Popular Posts Widget 0.8

The Most Popular Posts Widget plugin for WordPress is vulnerable to a type of attack known as SQL Injection. This kind of attack is possible because of insufficient escaping on user supplied parameters and insufficient preparation of the existing SQL query in versions up to and including 0.8. An attacker with administrator-level or higher access can use this vulnerability to append additional SQL queries to the existing queries, allowing them to access sensitive information from the database.

Detected in:

Most Popular Posts Widget fixed vulnerable versions: >= * <= 0.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.