Input validation vulnerability in Ultimate Maps by Supsystic 1.1.17

The Ultimate Maps by Supsystic plugin for WordPress is not secure in versions up to 1.1.16. Attackers with a certain level of access can use this vulnerability to get information from the database that should be kept secret. This is done by adding extra SQL queries to existing ones, and the vulnerability is caused by not escaping user supplied parameters and not sufficiently preparing the SQL queries.

Detected in:

Ultimate Maps by Supsystic fixed vulnerable versions: >= * < 1.1.17

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.