Input validation vulnerability in iATS Online Forms 1.2

The iATS Online Forms plugin for WordPress has a security issue that allows attackers to access sensitive information in the database. This happens when they manipulate the ‘order’ parameter, which is not properly protected and is not checked before being used in the database. This vulnerability affects all versions up to and including 1.2, and can only be exploited by users with Contributor-level access or higher.

Detected in:

iATS Online Forms open vulnerable versions: >= * <= 1.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.