Input validation vulnerability in Wp photo text slider 50 8.0

The Wp Photo Text Slider 50 plugin for WordPress, up to version 8.0, has a security flaw which makes it vulnerable to a type of attack called SQL Injection. This type of attack is possible because the plugin’s shortcode does not escape user-supplied parameters properly, and the existing SQL query is not prepared correctly. People with subscriber-level or higher user permissions can take advantage of this flaw and add additional SQL queries to the existing ones, potentially allowing them to access sensitive information from the database.

Detected in:

Wp photo text slider 50 open vulnerable versions: >= * <= 8.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.