Input validation vulnerability in Ultimate Addons for Contact Form 7 3.1.23

The Ultimate Addons for Contact Form 7 plugin for WordPress is vulnerable to a type of attack called SQL Injection. This is possible when the version of the plugin is up to, and including, 3.1.23. The reason this is possible is because the plugin does not properly protect the user supplied information and does not properly prepare the existing SQL query. This type of attack can be used by unauthenticated attackers to gain access to sensitive information from the database.

Detected in:

Ultimate Addons for Contact Form 7 fixed vulnerable versions: >= * <= 3.1.23
Ultra Addons for Contact Form 7 fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.