Input validation vulnerability in BigContact Contact Page 1.4.7

The BigContact Contact Page plugin for WordPress has a security issue which could allow an attacker with the proper permissions to access sensitive information from the database. This vulnerability exists in versions of the plugin that are before 1.4.7, and happens because the plugin is not properly escaping user input and also not preparing the existing SQL query. This could allow an attacker to add additional SQL queries into the existing query, which could be used to extract sensitive information from the database.

Detected in:

BigContact Contact Page open vulnerable versions: >= * < 1.4.7

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.