Input validation vulnerability in SearchIQ – The Search Solution 3.8

The SearchIQ WordPress plugin before version 3.9 had a setting that could be changed to turn off checking for an extra layer of security. This setting allowed people to access a part of the plugin that was vulnerable to a type of attack called Cross-Site Scripting. This type of attack could allow hackers to inject malicious code into the plugin without being stopped by the extra layer of security. This was possible because the plugin did not have any protection to check and make sure the code was safe.

Detected in:

SearchIQ – The Search Solution fixed vulnerable versions: >= * <= 3.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.