Input validation vulnerability in WP Shop 3.4.3.16

The WP Shop plugin for WordPress is potentially vulnerable to attacks where an unauthenticated user can access sensitive information from the database. This is due to an issue with the user supplied “wpshop_id” parameter in versions up to 3.4.3.15. The parameter is not sufficiently escaped, and the existing SQL query is not properly prepared, making it possible for additional SQL queries to be appended, allowing access to the database.

Detected in:

WP Shop open vulnerable versions: >= * < 3.4.3.16

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.