Input validation vulnerability in FrieChat – WordPress Chat Plugin 1.0.3

The WordPress Chat Plugin for WordPress, called FrieChat, is vulnerable to an attack called Generic SQL Injection in versions before 1.0.3. This is because it does not escape user-supplied information and does not prepare existing SQL queries properly. This makes it possible for anyone to add extra SQL queries to the existing queries, which can be used to get sensitive information from the database.

Detected in:

FrieChat - WordPress Chat Plugin fixed vulnerable versions: >= * < 1.0.3

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.