Input validation vulnerability in ArtPlacer Widget 2.20.6

The ArtPlacer Widget plugin for the WordPress website content management system is vulnerable to SQL Injection. This is because the ‘id’ parameter in versions up to and including 2.20.6 is not properly escaped from user input, and the existing SQL query is not prepared properly. This means that attackers who have access to the website at the ‘editor’ level or higher can inject additional SQL queries that allow them to extract sensitive information from the website’s database.

Detected in:

ArtPlacer Widget fixed vulnerable versions: >= * <= 2.20.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.