Input validation vulnerability in Transposh WordPress Translation 1.0.8.1

The Transposh WordPress Translation plugin for WordPress is not secure in versions up to 1.0.8.1. An attacker with administrative level permissions can use a technique called SQL Injection to access sensitive information from the database. This is made possible because the plugin does not escape user-supplied parameters or prepare existing SQL queries correctly.

Detected in:

Transposh WordPress Translation open vulnerable versions: >= * <= 1.0.9.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.