Input validation vulnerability in Administrator Z 2024.11.02

The plugin called Administrator Z for WordPress has a security issue called SQL Injection. This can be found in versions up to and including 2024.11.02. It happens because the plugin does not properly handle certain information from users and does not adequately prepare the SQL query. This means that someone who is logged in and has at least subscriber-level access can add their own SQL queries to ones that already exist, which could result in private information being taken from the database.

Detected in:

Administrator Z open vulnerable versions: >= * <= 2024.10.14

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.