Black Friday Deals 40% OFF

Days
Hours
Minutes

Input validation vulnerability in One to one user Chat by WPGuppy 1.1.0

The WPGuppy plugin for WordPress has a security issue called PHP Object Injection, which allows unauthorized people to insert a PHP Object. This can happen in versions 1.1.0 and below when untrusted input is deserialized. There is no known way for attackers to do this, but if they have access to other plugins or themes on the website, they could potentially delete files, access private information, or run their own code.

Detected in:

One to one user Chat by WPGuppy fixed vulnerable versions: >= * <= 1.1.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.