Input validation vulnerability in Membership by Supsystic 1.5.0

The Membership by Supsystic plugin for WordPress is vulnerable to a security issue in versions up to, and including, 1.5.0. This issue can allow an authenticated attacker to access sensitive information from the database. The vulnerable code is caused by the lack of sufficient escaping of the user-supplied parameters, and the lack of preparation of the existing SQL query. This makes it possible for the attacker to add additional SQL queries to the existing query, which can lead to the sensitive information being exposed.

Detected in:

Membership by Supsystic open vulnerable versions: >= * <= 1.5.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.